Lucene search

K
ciscoCiscoCISCO-SA-20150629-CVE-2015-4226
HistoryJun 29, 2015 - 6:05 p.m.

Cisco Unified IP Phones 9900 Series Denial of Service Vulnerability

2015-06-2918:05:35
tools.cisco.com
19

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

65.8%

A vulnerability in the packet storing capabilities of Cisco 9900 Series IP Phones could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

The vulnerability is due to how the phone decoder handles certain real-time transport protocol (RTP) packets. An attacker could exploit this vulnerability by calling a registered phone, waiting for a user to answer, then send malformed RTP packets to the user’s phone. A successful exploit could cause the phone to become unresponsive, resulting in a DoS condition.

Cisco has confirmed the vulnerability and released software updates.

To exploit this vulnerability, an attacker must first call a targeted phone and then rely on a user to answer the phone prior to sending malformed RTP packets. The attacker can not exploit this vulnerability without this requirement.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscounified_ip_phones_9900_series_firmwareMatchany
OR
ciscounified_ip_phones_9951_firmwareMatch9900_series_firmware
VendorProductVersionCPE
ciscounified_ip_phones_9900_series_firmwareanycpe:2.3:o:cisco:unified_ip_phones_9900_series_firmware:any:*:*:*:*:*:*:*
ciscounified_ip_phones_9951_firmware9900_series_firmwarecpe:2.3:o:cisco:unified_ip_phones_9951_firmware:9900_series_firmware:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

AI Score

6.8

Confidence

High

EPSS

0.003

Percentile

65.8%

Related for CISCO-SA-20150629-CVE-2015-4226