CVE-2018-0332: High severity cisco unified ip phone firmware vulnerability
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit this vulnerability by sending high volumes of SIP INVITE traffic to the targeted device. Successful exploitation could allow the attacker to cause a disruption of services on the targeted IP phone. Cisco Bug IDs: CSCve10064, CSCve14617, CSCve14638, CSCve14683, CSCve20812, CSCve20926, CSCve20945.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0332?
CVE-2018-0332 is a vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software.
How does CVE-2018-0332 affect Cisco Unified IP Phone firmware version 9.9 (9.99002.1)?
CVE-2018-0332 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition if they target a Cisco Unified IP Phone firmware version 9.9 (9.99002.1).
What is the severity of CVE-2018-0332?
CVE-2018-0332 has a severity value of 7.5 (high).
How can I fix the vulnerability in Cisco Unified IP Phone firmware version 9.9 (9.99002.1) caused by CVE-2018-0332?
There is currently no known fix for the vulnerability in Cisco Unified IP Phone firmware version 9.9 (9.99002.1) caused by CVE-2018-0332. It is recommended to monitor the Cisco Security Advisory for any updates or patches.
Where can I find more information about CVE-2018-0332?
You can find more information about CVE-2018-0332 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/104445), [SecurityTracker](http://www.securitytracker.com/id/1041074), [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-ip-phone-dos)