CVE-2018-0332
HIGHCisco Unified IP Phone Firmware - Unauthenticated Denial of Service via SIP INVITE Flood
Title source: llmDescription
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit this vulnerability by sending high volumes of SIP INVITE traffic to the targeted device. Successful exploitation could allow the attacker to cause a disruption of services on the targeted IP phone. Cisco Bug IDs: CSCve10064, CSCve14617, CSCve14638, CSCve14683, CSCve20812, CSCve20926, CSCve20945.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104445
Vendor Advisory x_refsource_confirm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-ip-phone-dos
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1041074
Scores
CVSS v3
7.5
EPSS
0.0348
EPSS Percentile
87.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-399
Status
published
Products (3)
cisco/ip_phone_firmware
9.4\(2\)sr3.1
cisco/ip_phone_firmware
9.4\(2\)sr4
cisco/unified_ip_phone_firmware
9.9\(9.99002.1\)
Published
Jun 07, 2018
Tracked Since
Feb 18, 2026