cisco-sa-20180606-ip-phone-dos: Cisco Unified IP Phone Software Denial of Service Vulnerability
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit this vulnerability by sending high volumes of SIP INVITE traffic to the targeted device. Successful exploitation could allow the attacker to cause a disruption of services on the targeted IP phone.
There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-ip-phone-dos
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20180606-ip-phone-dos?
The severity of cisco-sa-20180606-ip-phone-dos is classified as high due to its potential to cause a denial of service.
How do I fix cisco-sa-20180606-ip-phone-dos?
To fix cisco-sa-20180606-ip-phone-dos, you should upgrade to the fixed version of the Cisco Unified IP Phone Software as provided by Cisco.
What causes cisco-sa-20180606-ip-phone-dos?
cisco-sa-20180606-ip-phone-dos is caused by a lack of flow-control mechanisms in the SIP ingress packet processing of the affected software.
Who is affected by cisco-sa-20180606-ip-phone-dos?
cisco-sa-20180606-ip-phone-dos affects users of Cisco Unified IP Phone Software.
Can cisco-sa-20180606-ip-phone-dos be exploited remotely?
Yes, cisco-sa-20180606-ip-phone-dos can be exploited by an unauthenticated remote attacker.