Unknown
CVE-2019-1922
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- ip conference phone 7832 firmware -,
- ip conference phone 8832 firmware 11.5(1),
- ip conference phone 8832 firmware 12.5(1),
- ip phone 7811 firmware -,
- ip phone 7821 firmware -,
- ip phone 7841 firmware -,
- ip phone 7861 firmware -,
- ip phone 8811 firmware 11.5(1),
- ip phone 8811 firmware 12.5(1),
- ip phone 8841 firmware 11.5(1),
- ip phone 8841 firmware 12.5(1),
- ip phone 8845 firmware 11.5(1),
- ip phone 8845 firmware 12.5(1),
- ip phone 8851 firmware 11.5(1),
- ip phone 8851 firmware 12.5(1),
- ip phone 8861 firmware 11.5(1),
- ip phone 8861 firmware 12.5(1),
- ip phone 8865 firmware 11.5(1),
- ip phone 8865 firmware 12.5(1)
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: