← Back

CVE-2018-0316

nvd nist
Published: Jun 7, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability exists because the firmware of an affected phone incorrectly handles errors that could occur when an incoming phone call is not answered. An attacker could exploit this vulnerability by sending a set of maliciously crafted SIP packets to an affected phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, resulting in a temporary DoS condition. This vulnerability affects Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware if they are running a Multiplatform Firmware release prior to Release 11.1(2). Cisco Bug IDs: CSCvi24718.

Affected (1)

1 product
Ip Phone Firmware
Configuration A
1 vulnerable · 12 platform
Vulnerable SoftwareAffected Versions
Version 11.1(2)
Running on/withPlatform Versions
Cisco
Ip Phone 6841
All versions
Cisco
Ip Phone 6851
All versions
Cisco
Ip Phone 7811
All versions
Cisco
Ip Phone 7821
All versions
Cisco
Ip Phone 7841
All versions
Cisco
Ip Phone 7861
All versions
Cisco
Ip Phone 8811
All versions
Cisco
Ip Phone 8841
All versions
Cisco
Ip Phone 8845
All versions
Cisco
Ip Phone 8851
All versions
Cisco
Ip Phone 8861
All versions
Cisco
Ip Phone 8865
All versions

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.