CVE-2013-5526: Input Validation
Published Oct 10, 2013
·Updated
Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.
Affected Software
2 affected components
cisco Unified Ip Phone 9951
cisco Unified Ip Phone 9971
Event History
Oct 10, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5526?
CVE-2013-5526 is classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2013-5526?
To mitigate CVE-2013-5526, Cisco recommends updating to the latest firmware for affected IP phones.
3
What devices are affected by CVE-2013-5526?
CVE-2013-5526 specifically affects Cisco Unified IP Phone 9951 and Cisco Unified IP Phone 9971.
4
What type of attack does CVE-2013-5526 enable?
CVE-2013-5526 allows remote attackers to execute denial of service by sending crafted SDP packets.
5
What is the impact of CVE-2013-5526 on Cisco 9900 series phones?
The impact of CVE-2013-5526 on Cisco 9900 series phones includes the potential for device reboot and disruption of service.