First published: Mon Sep 12 2016(Updated: )
The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of malformed HTTP requests, aka Bug ID CSCut67385.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco SPA300 Firmware | <=7.5.7\(6\) | |
Cisco SPA 500 Series IP Phone Firmware | <=7.5.7\(6\) | |
Cisco SPA300 Series IP Phone | ||
Cisco SPA500 Series IP Phones firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1469 is classified as a denial of service vulnerability that can affect the operation of Cisco SPA300, SPA500, and SPA51x devices.
To mitigate CVE-2016-1469, you should upgrade the firmware of affected Cisco devices to a version higher than 7.5.7(6).
CVE-2016-1469 affects Cisco SPA300, SPA500, and SPA51x devices running firmware versions up to 7.5.7(6).
Yes, CVE-2016-1469 can be exploited remotely by sending malformed HTTP requests to the affected devices.
The exploit of CVE-2016-1469 can lead to a denial of service, causing the affected Cisco devices to become unresponsive.