CVE-2008-0526: Input Validation
Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0526?
CVE-2008-0526 is considered a high severity vulnerability as it allows remote attackers to cause a denial of service by rebooting the affected Cisco Unified IP Phones.
How do I fix CVE-2008-0526?
To mitigate CVE-2008-0526, ensure that the affected Cisco Unified IP Phones are updated to the latest firmware that addresses this vulnerability.
Which devices are affected by CVE-2008-0526?
CVE-2008-0526 affects Cisco Unified IP Phone models 7940, 7940G, 7960, and 7960G running SCCP firmware.
What type of attack does CVE-2008-0526 enable?
CVE-2008-0526 enables a denial of service attack that can reboot the affected Cisco Unified IP Phones.
Is there a workaround for CVE-2008-0526?
Disabling remote access or restricting ICMP traffic can serve as a temporary workaround for CVE-2008-0526.