← Back

CVE-2003-1109

nvd nist
Published: Dec 31, 2003Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

Affected (75)

4 products
Ios
Ip Phone 7940
Ip Phone 7960
Pix Firewall Software
Configuration A
75 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 12.2(11)t
Version 12.2(1)xa
Version 12.2(1)xd1
Version 12.2(1)xd3
Version 12.2(1)xd4
Version 12.2(1)xd
Version 12.2(1)xe2
Version 12.2(1)xe3
Version 12.2(1)xe
Version 12.2(1)xh
Version 12.2(1)xq
Version 12.2(1)xs1
Version 12.2(1)xs
Version 12.2(2)t4
Version 12.2(2)xa1
Version 12.2(2)xa5
Version 12.2(2)xa
Version 12.2(2)xb3
Version 12.2(2)xb4
Version 12.2(2)xb
Version 12.2(2)xf
Version 12.2(2)xg
Version 12.2(2)xh2
Version 12.2(2)xh3
Version 12.2(2)xh
Version 12.2(2)xi1
Version 12.2(2)xi2
Version 12.2(2)xi
Version 12.2(2)xj1
Version 12.2(2)xj
Version 12.2(2)xk2
Version 12.2(2)xk
Version 12.2(2)xn
Version 12.2(2)xt3
Version 12.2(2)xt
Version 12.2(2)xu2
Version 12.2(2)xu
Version 12.2t
Version 12.2xa
Version 12.2xb
Version 12.2xc
Version 12.2xd
Version 12.2xe
Version 12.2xf
Version 12.2xg
Version 12.2xh
Version 12.2xi
Version 12.2xj
Version 12.2xk
Version 12.2xl
Version 12.2xm
Version 12.2xn
Version 12.2xq
Version 12.2xr
Version 12.2xs
Version 12.2xt
Version 12.2xw
All versions
All versions
Cisco
Version 5.2(1)
Version 5.2(2)
Version 5.2(3.210)
Version 5.2(5)
Version 5.2(6)
Version 5.2(7)
Version 5.3
Version 5.3(1.200)
Version 5.3(1)
Version 5.3(2)
Version 5.3(3)
Version 6.0
Version 6.0(1)
Version 6.0(2)
Version 6.1(2)
Version 6.2(1)

References (18)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.