First published: Tue Jun 13 2017(Updated: )
A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the SIP process unexpectedly restarting. All active phone calls are dropped as the SIP process restarts. More Information: CSCvc29353. Known Affected Releases: 11.0(0.1). Known Fixed Releases: 11.0(0)MP2.153 11.0(0)MP2.62.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IP Phone 8800 Series Software | =11.0\(0.1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6656 is classified as a denial of service vulnerability affecting Cisco IP Phone 8800 Series devices.
To remediate CVE-2017-6656, upgrade the Cisco IP Phone 8800 Series software to the latest version that addresses the vulnerability.
CVE-2017-6656 specifically affects the Cisco IP Phone 8800 Series devices running version 11.0(0.1).
CVE-2017-6656 can cause an unexpected restart of the SIP process, resulting in dropped active phone calls and potential service disruption.
No, CVE-2017-6656 can be exploited by an unauthenticated remote attacker.