First published: Fri Mar 22 2019(Updated: )
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code. The vulnerability exists because the software improperly validates user-supplied input during user authentication. An attacker could exploit this vulnerability by connecting to an affected device using HTTP and supplying malicious user credentials. A successful exploit could allow the attacker to trigger a reload of an affected device, resulting in a DoS condition, or to execute arbitrary code with the privileges of the app user. Cisco fixed this vulnerability in the following SIP Software releases: 10.3(1)SR5 and later for Cisco Unified IP Conference Phone 8831; 11.0(4)SR3 and later for Cisco Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 and later for the rest of the Cisco IP Phone 7800 Series and 8800 Series.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Ip Phone 8821 Firmware | <11.0\(4\)sr3 | |
Cisco Ip Phone 8821 | ||
Cisco Ip Phone 8821-ex Firmware | <11.0\(4\)sr3 | |
Cisco Ip Phone 8821-ex | ||
Cisco Ip Conference Phone 7800 Firmware | <12.5\(1\)sr1 | |
Cisco Ip Conference Phone 7800 | ||
Cisco Ip Phone 8800 Firmware | <12.5\(1\)sr1 | |
Cisco IP Phone 8800 | ||
Cisco Unified Ip Conferenece Phone 8831 Firmware | <10.3\(1\)sr5 | |
Cisco Unified Ip Conferenece Phone 8831 | ||
All of | ||
Cisco Ip Phone 8821 Firmware | <11.0\(4\)sr3 | |
Cisco Ip Phone 8821 | ||
All of | ||
Cisco Ip Phone 8821-ex Firmware | <11.0\(4\)sr3 | |
Cisco Ip Phone 8821-ex | ||
All of | ||
Cisco Ip Conference Phone 7800 Firmware | <12.5\(1\)sr1 | |
Cisco Ip Conference Phone 7800 | ||
All of | ||
Cisco Ip Phone 8800 Firmware | <12.5\(1\)sr1 | |
Cisco IP Phone 8800 | ||
All of | ||
Cisco Unified Ip Conferenece Phone 8831 Firmware | <10.3\(1\)sr5 | |
Cisco Unified Ip Conferenece Phone 8831 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-1716.
The severity of CVE-2019-1716 is critical with a score of 9.8.
The affected software includes Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series.
CVE-2019-1716 allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code.
To fix CVE-2019-1716, it is recommended to apply the necessary patches provided by Cisco.