The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Computer vulnerabilities of Cisco IP Phone

vulnerability note CVE-2019-1683

Cisco IP Phone SPAx: privilege escalation via Certificate Validation

Synthesis of the vulnerability

An attacker can bypass restrictions via Certificate Validation of Cisco IP Phone SPAx, in order to escalate his privileges.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: data reading, data creation/edition.
Provenance: LAN.
Creation date: 21/02/2019.
Identifiers: CERTFR-2019-AVI-073, cisco-sa-20190220-ipphone-certs, CSCvm49157, CSCvn17125, CSCvn17128, CVE-2019-1683, VIGILANCE-VUL-28574.

Description of the vulnerability

An attacker can bypass restrictions via Certificate Validation of Cisco IP Phone SPAx, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

vulnerability bulletin CVE-2019-1684

Cisco IP Phone 7800/8800: denial of service via CDP/LLDP

Synthesis of the vulnerability

An attacker can trigger a fatal error via CDP/LLDP of Cisco IP Phone 7800/8800, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: LAN.
Creation date: 21/02/2019.
Identifiers: CERTFR-2019-AVI-073, cisco-sa-20190220-cdp-lldp-dos, CSCvn47250, CSCvo54699, CSCvo55040, CVE-2019-1684, VIGILANCE-VUL-28573.

Description of the vulnerability

An attacker can trigger a fatal error via CDP/LLDP of Cisco IP Phone 7800/8800, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability bulletin CVE-2018-0461

Cisco IP Phone 8800: privilege escalation via Script Injection

Synthesis of the vulnerability

An attacker can bypass restrictions via Script Injection of Cisco IP Phone 8800, in order to escalate his privileges.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: administrator access/rights, privileged access/rights, user access/rights.
Provenance: document.
Creation date: 10/01/2019.
Identifiers: cisco-sa-20190109-phone-script-injection, CSCvm95999, CVE-2018-0461, SA-20190109-0, VIGILANCE-VUL-28208.

Description of the vulnerability

An attacker can bypass restrictions via Script Injection of Cisco IP Phone 8800, in order to escalate his privileges.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2018-15434

Cisco Unified IP Phone 7900: Cross Site Scripting

Synthesis of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Unified IP Phone 7900, in order to run JavaScript code in the context of the web site.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: client access/rights.
Provenance: document.
Creation date: 04/10/2018.
Identifiers: CERTFR-2018-AVI-468, cisco-sa-20181003-uipp-7900-xss, CSCvj73657, CVE-2018-15434, VIGILANCE-VUL-27410.

Description of the vulnerability

An attacker can trigger a Cross Site Scripting of Cisco Unified IP Phone 7900, in order to run JavaScript code in the context of the web site.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2018-5391

Linux kernel: denial of service via FragmentSmack

Synthesis of the vulnerability

An attacker can generate a fatal error via FragmentSmack of the Linux kernel, in order to trigger a denial of service.
Impacted products: GAiA, SecurePlatform, CheckPoint Security Gateway, Cisco Aironet, IOS XE Cisco, Nexus by Cisco, Prime Collaboration Assurance, Prime Infrastructure, Cisco Router, Secure ACS, Cisco CUCM, Cisco UCS, Cisco Unified CCX, Cisco IP Phone, Cisco Wireless Controller, Debian, BIG-IP Hardware, TMOS, Junos Space, Linux, Windows 10, Windows 2008 R0, Windows 2008 R2, Windows 2012, Windows 2016, Windows 7, Windows 8, Windows RT, openSUSE Leap, Palo Alto Firewall PA***, PAN-OS, RHEL, SUSE Linux Enterprise Desktop, SLES, Symantec Content Analysis, ProxySG by Symantec, Synology DSM, Ubuntu.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: internet client.
Creation date: 16/08/2018.
Identifiers: ADV180022, CERTFR-2018-AVI-390, CERTFR-2018-AVI-392, CERTFR-2018-AVI-419, CERTFR-2018-AVI-457, CERTFR-2018-AVI-478, CERTFR-2018-AVI-533, cisco-sa-20180824-linux-ip-fragment, CVE-2018-5391, DLA-1466-1, DLA-1529-1, DSA-4272-1, FragmentSmack, JSA10917, K74374841, openSUSE-SU-2018:2404-1, openSUSE-SU-2018:2407-1, openSUSE-SU-2019:0274-1, PAN-SA-2018-0012, RHSA-2018:2785-01, RHSA-2018:2791-01, RHSA-2018:2846-01, RHSA-2018:2924-01, RHSA-2018:2925-01, RHSA-2018:2933-01, RHSA-2018:2948-01, RHSA-2018:3083-01, RHSA-2018:3096-01, RHSA-2018:3459-01, RHSA-2018:3540-01, RHSA-2018:3586-01, RHSA-2018:3590-01, sk134253, SUSE-SU-2018:2344-1, SUSE-SU-2018:2374-1, SUSE-SU-2018:2380-1, SUSE-SU-2018:2381-1, SUSE-SU-2018:2596-1, SUSE-SU-2019:0541-1, SYMSA1467, Synology-SA-18:44, USN-3740-1, USN-3740-2, USN-3741-1, USN-3741-2, USN-3741-3, USN-3742-1, USN-3742-2, USN-3742-3, VIGILANCE-VUL-27009, VU#641765.

Description of the vulnerability

An attacker can generate a fatal error via FragmentSmack of the Linux kernel, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability note CVE-2018-0341

Cisco IP Phone: code execution via Shell Command Injection

Synthesis of the vulnerability

An attacker can use a vulnerability via Shell Command Injection of Cisco IP Phone, in order to run code.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: administrator access/rights, privileged access/rights, user access/rights.
Provenance: user shell.
Creation date: 12/07/2018.
Identifiers: CERTFR-2018-AVI-341, cisco-sa-20180711-phone-webui-inject, CSCvi51426, CVE-2018-0341, VIGILANCE-VUL-26699.

Description of the vulnerability

An attacker can use a vulnerability via Shell Command Injection of Cisco IP Phone, in order to run code.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability CVE-2018-0316

Cisco Unified IP Phone: denial of service via Multiplatform Firmware SIP

Synthesis of the vulnerability

An attacker can generate a fatal error via Multiplatform Firmware SIP of Cisco Unified IP Phone, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: intranet client.
Creation date: 07/06/2018.
Identifiers: CERTFR-2018-AVI-270, cisco-sa-20180606-multiplatform-sip, CSCvi24718, CVE-2018-0316, VIGILANCE-VUL-26345.

Description of the vulnerability

An attacker can generate a fatal error via Multiplatform Firmware SIP of Cisco Unified IP Phone, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability note CVE-2018-0332

Cisco Unified IP Phone: denial of service via SIP INVITE

Synthesis of the vulnerability

An attacker can generate a fatal error via SIP INVITE of Cisco Unified IP Phone, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: intranet client.
Creation date: 07/06/2018.
Identifiers: CERTFR-2018-AVI-270, cisco-sa-20180606-ip-phone-dos, CVE-2018-0332, VIGILANCE-VUL-26344.

Description of the vulnerability

An attacker can generate a fatal error via SIP INVITE of Cisco Unified IP Phone, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

computer vulnerability CVE-2018-0325

Cisco IP Phone 7800/8800/8821: denial of service via SIP SDP

Synthesis of the vulnerability

An attacker can generate a fatal error via SIP SDP of Cisco IP Phone 7800/8800/8821, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service, denial of service on client.
Provenance: intranet client.
Creation date: 17/05/2018.
Identifiers: CERTFR-2018-AVI-240, cisco-sa-20180516-ip-phone-dos, CSCvf40066, CSCvj73508, CVE-2018-0325, VIGILANCE-VUL-26155.

Description of the vulnerability

An attacker can generate a fatal error via SIP SDP of Cisco IP Phone 7800/8800/8821, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)

vulnerability CVE-2017-12328

Cisco IP Phone 8800: denial of service via SIP

Synthesis of the vulnerability

An attacker can send malicious SIP packets to Cisco IP Phone 8800, in order to trigger a denial of service.
Impacted products: Cisco IP Phone.
Severity: 2/4.
Consequences: denial of service on server, denial of service on service.
Provenance: intranet client.
Creation date: 30/11/2017.
Identifiers: cisco-sa-20171129-ipp, CSCvc62590, CVE-2017-12328, VIGILANCE-VUL-24580.

Description of the vulnerability

An attacker can send malicious SIP packets to Cisco IP Phone 8800, in order to trigger a denial of service.
Full Vigil@nce bulletin... (Free trial)
Our database contains other pages. You can request a free trial to read them.

Display information about Cisco IP Phone: