Click Icon to Copy Verbose Score
AV:A/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
-
Cisco 7940 and 7960 IP Phones with firmware versions 8.6 and prior contain a vulnerability when handling a series of SIP messages that could allow an attacker on the Voice VLAN to cause the phone to fail and restart.
This vulnerability exists due to insufficient handling of certain sets of malformed SIP messages that are sent to affected devices. An unauthenticated, remote attacker with access to the voice VLAN could exploit this vulnerability by sending a series of malicious SIP messages to an affected device. When a device processes these messages, the device may fail and restart. An exploit could result in a denial of service condition.
Exploit code is available.
Cisco confirmed this vulnerability, and updated software is available.
To exploit this vulnerability, an attacker must have access to networks where the affected devices are located. Depending on site configuration, IP phones could reside on separate physical or logical networks. An exploit could allow the attacker to render an affected device unavailable, which may result in a denial of service condition. However, an attacker could not gain access to confidential information or gain any additional privileges as a result of a successful attack.
This vulnerability appears to be a state management bug. When the affected devices respond to a specific sequence of SIP messages, the phone may corrupt its state table, which could result in a crash that triggers a reboot of the device.
Cisco 7940 and 7960 IP phones running firmware version 8.7 are not affected by this vulnerability, as this version contains the correction.
-
Cisco has released a security advisory to address Cisco Bug ID CSCsi68191 at the following link: cisco-sr-20070821-sip
-
Administrators are advised to apply the appropriate update.
Administrators are advised to place all IP phones on an isolated network or VLAN. This action will help prevent outside attackers from exploiting this vulnerability.
Administrators are advised to maintain physical security on IP phone ports. Any unused ports should be disabled until they are necessary.
-
Cisco customers with active contracts can obtain updates through the Software Center at the following link: Cisco. Cisco customers without contracts can obtain upgrades by contacting the Cisco Technical Assistance Center at 1-800-553-2447 or 1-408-526-7209 or via e-mail at tac@cisco.com.
-
The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
-
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
-
Show LessVersion Description Section Status Date 1.0 Initial Release NA Final 2007-Aug-21
-
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
A stand-alone copy or paraphrase of the text of this document that omits the distribution URL is an uncontrolled copy, and may lack important information or contain factual errors. The information in this document is intended for end-users of Cisco products.