CVE-2018-0325
Last modified
CVE-2018-0325 is a vulnerability of currently unknown severity. A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 7800 Series phones and Cisco IP Phone 8800 Series phones could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to incomplete input validation of SIP Session Description Protocol (SDP) parameters by the SDP parser of an affected phone. EPSS estimates a 3.38% chance of exploitation in the next 30 days.
Description
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 7800 Series phones and Cisco IP Phone 8800 Series phones could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to incomplete input validation of SIP Session Description Protocol (SDP) parameters by the SDP parser of an affected phone. An attacker could exploit this vulnerability by sending a malformed SIP packet to an affected phone. A successful exploit could allow the attacker to cause all active phone calls on the affected phone to be dropped while the SIP process on the phone unexpectedly restarts, resulting in a DoS condition. Cisco Bug IDs: CSCvf40066.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ip Phone 8800 Firmware | 9.4\(2\)sr4 |
| Cisco | Ip Phone 8800 Firmware | 10.3\(1\)sr4 |
| Cisco | Ip Phone 7800 Firmware | < 12.1\(1.12\) |
| Cisco | Ip Phone 7800 Firmware | < 12.1\(1\)mn130 |
References
- http://www.securityfocus.com/bid/104202Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040927Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104202Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040927Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0325?
How severe is CVE-2018-0325?
How do I fix CVE-2018-0325?
Are you affected by CVE-2018-0325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
