myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron at myITforum.com

Sharing Security Developments, and Best Practices for corporate and home users

Cisco IP Phone 7940/7960 Denial of Service Vulnerability

Cisco phone users should apply the relevant patches if needed to prevent DoS based lockouts of service.  So far, there are no known exploits of this in the wild.  This one was of interest as I use a 7961 at work.

Cisco IP Phone 7940/7960 Denial of Service Vulnerability
http://secunia.com/advisories/24600/
http://www.frsirt.com/english/advisories/2007/1023

QUOTE: A vulnerability has been reported in Cisco IP Phone 7940 and 7960, which can be exploited by malicious people to cause a DoS (Denial of Service).  The vulnerability is caused due to an error within the handling of certain SIP INVITE messages. This can be exploited to reboot the device by sending a specially crafted INVITE message with a malformed "sipURI" field of the Remote-Party-ID. The vulnerability is reported in devices running firmware POS3-07-4-00.

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems