PT-2019-2053 · Cisco · Cisco Ip Phone 8800 Series+1

Published

2019-05-01

·

Updated

2020-10-16

·

CVE-2019-1635

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco IP Phone 7800 Series and 8800 Series (affected versions not specified)
Description The issue is related to errors in resource management in the call-handling functionality of Cisco IP Phone software. It could allow a remote attacker to cause a denial of service condition by sending a specially crafted SIP packet to the vulnerable phone. The vulnerability is due to incomplete error handling when XML data within a SIP packet is parsed. An attacker could exploit this by sending a SIP packet with a malicious XML payload, causing the phone to reload unexpectedly and resulting in a temporary denial of service condition.
Recommendations For Cisco IP Phone 7800 Series and 8800 Series, consider restricting access to SIP packets until a patch is available. As a temporary workaround, avoid using the SIP protocol with untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01798
CVE-2019-1635

Affected Products

Cisco Ip Phone 7800 Series
Cisco Ip Phone 8800 Series