CVE-2003-1109

UnknownEPSS 6.79%

Last modified

CVE-2003-1109 is a vulnerability of currently unknown severity. The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.. EPSS estimates a 6.79% chance of exploitation in the next 30 days.

Description

The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

Metrics

EPSS Probability
6.79%

93.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoIos12.2\(1\)xa
CiscoIos12.2\(1\)xd
CiscoIos12.2\(1\)xd1
CiscoIos12.2\(1\)xd3
CiscoIos12.2\(1\)xd4
CiscoIos12.2\(1\)xe
CiscoIos12.2\(1\)xe2
CiscoIos12.2\(1\)xe3
CiscoIos12.2\(1\)xh
CiscoIos12.2\(1\)xq
CiscoIos12.2\(1\)xs
CiscoIos12.2\(1\)xs1
CiscoIos12.2\(2\)t4
CiscoIos12.2\(2\)xa
CiscoIos12.2\(2\)xa1
CiscoIos12.2\(2\)xa5
CiscoIos12.2\(2\)xb
CiscoIos12.2\(2\)xb3
CiscoIos12.2\(2\)xb4
CiscoIos12.2\(2\)xf
CiscoIos12.2\(2\)xg
CiscoIos12.2\(2\)xh
CiscoIos12.2\(2\)xh2
CiscoIos12.2\(2\)xh3
CiscoIos12.2\(2\)xi
CiscoIos12.2\(2\)xi1
CiscoIos12.2\(2\)xi2
CiscoIos12.2\(2\)xj
CiscoIos12.2\(2\)xj1
CiscoIos12.2\(2\)xk
CiscoIos12.2\(2\)xk2
CiscoIos12.2\(2\)xn
CiscoIos12.2\(2\)xt
CiscoIos12.2\(2\)xt3
CiscoIos12.2\(2\)xu
CiscoIos12.2\(2\)xu2
CiscoIos12.2\(11\)t
CiscoIos12.2t
CiscoIos12.2xa
CiscoIos12.2xb
CiscoIos12.2xc
CiscoIos12.2xd
CiscoIos12.2xe
CiscoIos12.2xf
CiscoIos12.2xg
CiscoIos12.2xh
CiscoIos12.2xi
CiscoIos12.2xj
CiscoIos12.2xk
CiscoIos12.2xl

Showing 50 of 75 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2003-1109?
The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
How severe is CVE-2003-1109?
Severity scoring for CVE-2003-1109 is pending analysis. The EPSS model estimates a 6.79% probability of exploitation in the next 30 days.
How do I fix CVE-2003-1109?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2003-1109?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST