CVE-2019-12654: Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient sanity checks on an internal data structure. An attacker could exploit this vulnerability by sending a sequence of malicious SIP messages to an affected device. An exploit could allow the attacker to cause a NULL pointer dereference, resulting in a crash of the iosd process. This triggers a reload of the device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Cisco IOS and IOS XE SIP library vulnerability?
The vulnerability ID is CVE-2019-12654.
What is the severity of CVE-2019-12654?
The severity of CVE-2019-12654 is high, with a severity score of 7.5.
How does CVE-2019-12654 affect Cisco IOS and IOS XE Software?
CVE-2019-12654 could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
Which versions of Cisco IOS XE are affected by CVE-2019-12654?
Versions 15.6(1)s4.2, 16.3.8, and 16.9.1 of Cisco IOS XE are affected by CVE-2019-12654.
How can I fix the vulnerability identified in CVE-2019-12654?
To fix the vulnerability, Cisco recommends upgrading to a fixed software release.