The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Cisco IP Phone

computer vulnerability bulletin CVE-2019-1635

Cisco IP Phone: denial of service via SIP XML

Synthesis of the vulnerability

An attacker can trigger a fatal error via SIP XML of Cisco IP Phone, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on service, denial of service on client.
Provenance: intranet client.
Creation date: 02/05/2019.
Identifiers: CERTFR-2019-AVI-193, cisco-sa-20190501-phone-sip-xml-dos, CSCvm39405, CSCvo19825, CSCvo21348, CSCvo23532, CVE-2019-1635, VIGILANCE-VUL-29188.

Description of the vulnerability

An attacker can trigger a fatal error via SIP XML of Cisco IP Phone, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability alert CVE-2019-1766

Cisco IP Phone 8800: denial of service via SIP Web Management Interface File Upload

Synthesis of the vulnerability

An attacker can trigger a fatal error via SIP Web Management Interface File Upload of Cisco IP Phone 8800, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: intranet client.
Creation date: 21/03/2019.
Identifiers: cisco-sa-20190320-ipfudos, CSCvo58440, CVE-2019-1766, VIGILANCE-VUL-28796.

Description of the vulnerability

An attacker can trigger a fatal error via SIP Web Management Interface File Upload of Cisco IP Phone 8800, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability note CVE-2019-1764

Cisco IP Phone 8800: Cross Site Request Forgery

Synthesis of the vulnerability

An attacker can trigger a Cross Site Request Forgery of Cisco IP Phone 8800, in order to force the victim to perform operations.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: user access/rights.
Provenance: internet client.
Creation date: 21/03/2019.
Identifiers: cisco-sa-20190320-ip-phone-csrf, CSCvn56221, CSCvo57629, CVE-2019-1764, VIGILANCE-VUL-28794.

Description of the vulnerability

The Cisco IP Phone 8800 product offers a web service.

However, the origin of queries is not checked. They can for example originate from an image included in an HTML document.

An attacker can therefore trigger a Cross Site Request Forgery of Cisco IP Phone 8800, in order to force the victim to perform operations.
Full Vigil@nce bulletin... (Free trial)

vulnerability note CVE-2019-1683

Cisco IP Phone SPAx: privilege escalation via Certificate Validation

Synthesis of the vulnerability

An attacker can bypass restrictions via Certificate Validation of Cisco IP Phone SPAx, in order to escalate his privileges.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: data reading, data creation/edition.
Provenance: LAN.
Creation date: 21/02/2019.
Identifiers: CERTFR-2019-AVI-073, cisco-sa-20190220-ipphone-certs, CSCvm49157, CSCvn17125, CSCvn17128, CVE-2019-1683, VIGILANCE-VUL-28574.

Description of the vulnerability

An attacker can bypass restrictions via Certificate Validation of Cisco IP Phone SPAx, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

vulnerability bulletin CVE-2019-1684

Cisco IP Phone 7800/8800: denial of service via CDP/LLDP

Synthesis of the vulnerability

An attacker can trigger a fatal error via CDP/LLDP of Cisco IP Phone 7800/8800, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: LAN.
Creation date: 21/02/2019.
Identifiers: CERTFR-2019-AVI-073, cisco-sa-20190220-cdp-lldp-dos, CSCvn47250, CSCvo54699, CSCvo55040, CVE-2019-1684, VIGILANCE-VUL-28573.

Description of the vulnerability

An attacker can trigger a fatal error via CDP/LLDP of Cisco IP Phone 7800/8800, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability bulletin CVE-2018-0461

Cisco IP Phone 8800: privilege escalation via Script Injection

Synthesis of the vulnerability

An attacker can bypass restrictions via Script Injection of Cisco IP Phone 8800, in order to escalate his privileges.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: administrator access/rights, privileged access/rights, user access/rights.
Provenance: document.
Creation date: 10/01/2019.
Identifiers: cisco-sa-20190109-phone-script-injection, CSCvm95999, CVE-2018-0461, SA-20190109-0, VIGILANCE-VUL-28208.

Description of the vulnerability

An attacker can bypass restrictions via Script Injection of Cisco IP Phone 8800, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2018-15434

Cisco Unified IP Phone 7900: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Unified IP Phone 7900, in order to run JavaScript code in the context of the web site.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Creation date: 04/10/2018.
Identifiers: CERTFR-2018-AVI-468, cisco-sa-20181003-uipp-7900-xss, CSCvj73657, CVE-2018-15434, VIGILANCE-VUL-27410.

Description of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Unified IP Phone 7900, in order to run JavaScript code in the context of the web site.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2018-5391

Linux kernel: denial of service via FragmentSmack

Synthesis of the vulnerability

An attacker can generate a fatal error via FragmentSmack of the Linux kernel, in order to trigger a denial of service.
Impacted products: GAiA, SecurePlatform, CheckPoint Security Gateway, Cisco Aironet, IOS XE Cisco, Nexus by Cisco, Prime Collaboration Assurance, Prime Infrastructure, Cisco Router, Secure ACS, Cisco CUCM, Cisco UCS, Cisco Unified CCX, Cisco IP Phone, Cisco Wireless Controller, Debian, BIG-IP Hardware, TMOS, Junos Space, Linux, Windows 10, Windows 2008 R0, Windows 2008 R2, Windows 2012, Windows 2016, Windows 7, Windows 8, Windows RT, openSUSE Leap, Palo Alto Firewall PA***, PAN-OS, RHEL, RSA Authentication Manager, SUSE Linux Enterprise Desktop, SLES, Symantec Content Analysis, ProxySG by Symantec, Synology DSM, Ubuntu.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: internet client.
Creation date: 16/08/2018.
Identifiers: ADV180022, CERTFR-2018-AVI-390, CERTFR-2018-AVI-392, CERTFR-2018-AVI-419, CERTFR-2018-AVI-457, CERTFR-2018-AVI-478, CERTFR-2018-AVI-533, CERTFR-2019-AVI-233, CERTFR-2019-AVI-242, cisco-sa-20180824-linux-ip-fragment, CVE-2018-5391, DLA-1466-1, DLA-1529-1, DSA-2019-062, DSA-4272-1, FragmentSmack, JSA10917, K74374841, openSUSE-SU-2018:2404-1, openSUSE-SU-2018:2407-1, openSUSE-SU-2019:0274-1, PAN-SA-2018-0012, RHSA-2018:2785-01, RHSA-2018:2791-01, RHSA-2018:2846-01, RHSA-2018:2924-01, RHSA-2018:2925-01, RHSA-2018:2933-01, RHSA-2018:2948-01, RHSA-2018:3083-01, RHSA-2018:3096-01, RHSA-2018:3459-01, RHSA-2018:3540-01, RHSA-2018:3586-01, RHSA-2018:3590-01, sk134253, SUSE-SU-2018:2344-1, SUSE-SU-2018:2374-1, SUSE-SU-2018:2380-1, SUSE-SU-2018:2381-1, SUSE-SU-2018:2596-1, SUSE-SU-2019:0541-1, SUSE-SU-2019:1289-1, SYMSA1467, Synology-SA-18:44, USN-3740-1, USN-3740-2, USN-3741-1, USN-3741-2, USN-3741-3, USN-3742-1, USN-3742-2, USN-3742-3, VIGILANCE-VUL-27009, VU#641765.

Description of the vulnerability

An attacker can generate a fatal error via FragmentSmack of the Linux kernel, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2018-0341

Cisco IP Phone: code execution via Shell Command Injection

Synthesis of the vulnerability

An attacker can use a vulnerability via Shell Command Injection of Cisco IP Phone, in order to run code.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: administrator access/rights, privileged access/rights, user access/rights.
Provenance: user shell.
Creation date: 12/07/2018.
Identifiers: CERTFR-2018-AVI-341, cisco-sa-20180711-phone-webui-inject, CSCvi51426, CVE-2018-0341, VIGILANCE-VUL-26699.

Description of the vulnerability

An attacker can use a vulnerability via Shell Command Injection of Cisco IP Phone, in order to run code.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability CVE-2018-0316

Cisco Unified IP Phone: denial of service via Multiplatform Firmware SIP

Synthesis of the vulnerability

An attacker can generate a fatal error via Multiplatform Firmware SIP of Cisco Unified IP Phone, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: intranet client.
Creation date: 07/06/2018.
Identifiers: CERTFR-2018-AVI-270, cisco-sa-20180606-multiplatform-sip, CSCvi24718, CVE-2018-0316, VIGILANCE-VUL-26345.

Description of the vulnerability

An attacker can generate a fatal error via Multiplatform Firmware SIP of Cisco Unified IP Phone, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Cisco IP Phone: