CVE-2003-1109: High severity Cisco IOS vulnerability

Published Dec 31, 2003
·
Updated

The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

Affected Software

150 affected components
Cisco IOS=12.2\(1\)xa
Cisco IOS=12.2\(1\)xd
Cisco IOS=12.2\(1\)xd1
Cisco IOS=12.2\(1\)xd3
Cisco IOS=12.2\(1\)xd4
Cisco IOS=12.2\(1\)xe
Cisco IOS=12.2\(1\)xe2
Cisco IOS=12.2\(1\)xe3
Cisco IOS=12.2\(1\)xh
Cisco IOS=12.2\(1\)xq
Cisco IOS=12.2\(1\)xs
Cisco IOS=12.2\(1\)xs1
Cisco IOS=12.2\(2\)t4
Cisco IOS=12.2\(2\)xa
Cisco IOS=12.2\(2\)xa1
Cisco IOS=12.2\(2\)xa5
Cisco IOS=12.2\(2\)xb
Cisco IOS=12.2\(2\)xb3
Cisco IOS=12.2\(2\)xb4
Cisco IOS=12.2\(2\)xf
Cisco IOS=12.2\(2\)xg
Cisco IOS=12.2\(2\)xh
Cisco IOS=12.2\(2\)xh2
Cisco IOS=12.2\(2\)xh3
Cisco IOS=12.2\(2\)xi
Cisco IOS=12.2\(2\)xi1
Cisco IOS=12.2\(2\)xi2
Cisco IOS=12.2\(2\)xj
Cisco IOS=12.2\(2\)xj1
Cisco IOS=12.2\(2\)xk
Cisco IOS=12.2\(2\)xk2
Cisco IOS=12.2\(2\)xn
Cisco IOS=12.2\(2\)xt
Cisco IOS=12.2\(2\)xt3
Cisco IOS=12.2\(2\)xu
Cisco IOS=12.2\(2\)xu2
Cisco IOS=12.2\(11\)t
Cisco IOS=12.2t
Cisco IOS=12.2xa
Cisco IOS=12.2xb
Cisco IOS=12.2xc
Cisco IOS=12.2xd
Cisco IOS=12.2xe
Cisco IOS=12.2xf
Cisco IOS=12.2xg
Cisco IOS=12.2xh
Cisco IOS=12.2xi
Cisco IOS=12.2xj
Cisco IOS=12.2xk
Cisco IOS=12.2xl
Cisco IOS=12.2xm
Cisco IOS=12.2xn
Cisco IOS=12.2xq
Cisco IOS=12.2xr
Cisco IOS=12.2xs
Cisco IOS=12.2xt
Cisco IOS=12.2xw
Cisco IP Phone 7940
Cisco Ip Phone 7960
Cisco Pix Firewall Software=5.2\(1\)
Cisco Pix Firewall Software=5.2\(2\)
Cisco Pix Firewall Software=5.2\(3.210\)
Cisco Pix Firewall Software=5.2\(5\)
Cisco Pix Firewall Software=5.2\(6\)
Cisco Pix Firewall Software=5.2\(7\)
Cisco Pix Firewall Software=5.3
Cisco Pix Firewall Software=5.3\(1\)
Cisco Pix Firewall Software=5.3\(1.200\)
Cisco Pix Firewall Software=5.3\(2\)
Cisco Pix Firewall Software=5.3\(3\)
Cisco Pix Firewall Software=6.0
Cisco Pix Firewall Software=6.0\(1\)
Cisco Pix Firewall Software=6.0\(2\)
Cisco Pix Firewall Software=6.1\(2\)
Cisco Pix Firewall Software=6.2\(1\)
All of the following
Any of the following
Cisco IOS=12.2\(1\)xa
Cisco IOS=12.2\(1\)xd
Cisco IOS=12.2\(1\)xd1
Cisco IOS=12.2\(1\)xd3
Cisco IOS=12.2\(1\)xd4
Cisco IOS=12.2\(1\)xe
Cisco IOS=12.2\(1\)xe2
Cisco IOS=12.2\(1\)xe3
Cisco IOS=12.2\(1\)xh
Cisco IOS=12.2\(1\)xq
Cisco IOS=12.2\(1\)xs
Cisco IOS=12.2\(1\)xs1
Cisco IOS=12.2\(2\)t4
Cisco IOS=12.2\(2\)xa
Cisco IOS=12.2\(2\)xa1
Cisco IOS=12.2\(2\)xa5
Cisco IOS=12.2\(2\)xb
Cisco IOS=12.2\(2\)xb3
Cisco IOS=12.2\(2\)xb4
Cisco IOS=12.2\(2\)xf
Cisco IOS=12.2\(2\)xg
Cisco IOS=12.2\(2\)xh
Cisco IOS=12.2\(2\)xh2
Cisco IOS=12.2\(2\)xh3
Cisco IOS=12.2\(2\)xi
Cisco IOS=12.2\(2\)xi1
Cisco IOS=12.2\(2\)xi2
Cisco IOS=12.2\(2\)xj
Cisco IOS=12.2\(2\)xj1
Cisco IOS=12.2\(2\)xk
Cisco IOS=12.2\(2\)xk2
Cisco IOS=12.2\(2\)xn
Cisco IOS=12.2\(2\)xt
Cisco IOS=12.2\(2\)xt3
Cisco IOS=12.2\(2\)xu
Cisco IOS=12.2\(2\)xu2
Cisco IOS=12.2\(11\)t
Cisco IOS=12.2t
Cisco IOS=12.2xa
Cisco IOS=12.2xb
Cisco IOS=12.2xc
Cisco IOS=12.2xd
Cisco IOS=12.2xe
Cisco IOS=12.2xf
Cisco IOS=12.2xg
Cisco IOS=12.2xh
Cisco IOS=12.2xi
Cisco IOS=12.2xj
Cisco IOS=12.2xk
Cisco IOS=12.2xl
Cisco IOS=12.2xm
Cisco IOS=12.2xn
Cisco IOS=12.2xq
Cisco IOS=12.2xr
Cisco IOS=12.2xs
Cisco IOS=12.2xt
Cisco IOS=12.2xw
Any of the following
Cisco IP Phone 7940
Cisco Ip Phone 7960
Cisco Pix Firewall Software=5.2\(1\)
Cisco Pix Firewall Software=5.2\(2\)
Cisco Pix Firewall Software=5.2\(3.210\)
Cisco Pix Firewall Software=5.2\(5\)
Cisco Pix Firewall Software=5.2\(6\)
Cisco Pix Firewall Software=5.2\(7\)
Cisco Pix Firewall Software=5.3
Cisco Pix Firewall Software=5.3\(1\)
Cisco Pix Firewall Software=5.3\(1.200\)
Cisco Pix Firewall Software=5.3\(2\)
Cisco Pix Firewall Software=5.3\(3\)
Cisco Pix Firewall Software=6.0
Cisco Pix Firewall Software=6.0\(1\)
Cisco Pix Firewall Software=6.0\(2\)
Cisco Pix Firewall Software=6.1\(2\)
Cisco Pix Firewall Software=6.2\(1\)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    At the network perimeter and on SIP gateways, block, filter, or otherwise drop SIP INVITE messages from untrusted networks. Restrict SIP signaling to trusted peers using firewall/ACLs or SIP-aware gateways, and deploy SIP-aware IDS/IPS to detect and drop malformed INVITE messages (and/or rate-limit INVITE requests) to mitigate denial-of-service and exploitation attempts involving crafted INVITE messages.

Event History

Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
05:00 AM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Mar 11, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2003-1109?

The severity of CVE-2003-1109 is critical due to its potential to cause a denial of service and execute arbitrary code.

2

How do I fix CVE-2003-1109?

To fix CVE-2003-1109, update the affected Cisco products to the latest available software versions provided by Cisco.

3

Which Cisco products are affected by CVE-2003-1109?

CVE-2003-1109 affects multiple Cisco products including IP Phone models 7940 and 7960, various versions of Cisco IOS, and Secure PIX Firewall versions.

4

What type of attack can exploit CVE-2003-1109?

CVE-2003-1109 can be exploited by sending crafted INVITE messages which may lead to a denial of service or arbitrary code execution.

5

Is there a patch available for CVE-2003-1109?

Yes, Cisco has released patches for CVE-2003-1109; affected users should apply these updates immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203