Improper input validation in Cisco Systems, Inc products - CVE-2018-0332
Published: June 7, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software due to a lack of flow-control mechanisms in the software. A remote attacker can send high volumes of SIP INVITE traffic and cause a disruption of services on the targeted IP phone.
Affected software
Cisco 7800 Series IP Phones
Cisco Unified IP Phone 6900 Series
Cisco Unified IP Phones 9900 Series
Cisco Unified IP Phone 7900 Series