CVE-2015-0601: Input Validation
Published Feb 7, 2015
·Updated
Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790.
Affected Software
4 affected components
Cisco Unified Ip Phones 9971 Firmware<=9.4\(.1\)
Cisco Unified Ip Phone 9971
Cisco Unified Ip Phones 9951 Firmware<=9.4\(.1\)
Cisco Unified Ip Phone 9951
Event History
Feb 7, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0601?
CVE-2015-0601 is considered to have a significant severity due to its potential for local denial of service on affected Cisco Unified IP phones.
2
How do I fix CVE-2015-0601?
To fix CVE-2015-0601, upgrade the firmware of affected Cisco Unified IP phones to a version later than 9.4(.1).
3
Which devices are affected by CVE-2015-0601?
CVE-2015-0601 affects Cisco Unified IP Phones 9951 and 9971 with firmware versions 9.4(.1) and earlier.
4
What type of vulnerability is CVE-2015-0601?
CVE-2015-0601 is a local denial of service vulnerability allowing crafted commands to force a device reload.
5
Can CVE-2015-0601 be exploited remotely?
No, CVE-2015-0601 requires local access to the affected devices for exploitation.