CVE-2017-12219
Summary
| CVE | CVE-2017-12219 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-21 05:29:00 UTC |
| Updated | 2019-10-09 23:22:00 UTC |
| Description | A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to the inability to handle many large IP fragments for reassembly in a short duration. An attacker could exploit this vulnerability by sending a crafted stream of IP fragments to the targeted device. An exploit could allow the attacker to cause a DoS condition when the device unexpectedly reloads. Cisco Bug IDs: CSCve82586. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Spa 301 | - | All | All | All |
| Hardware | Cisco | Spa 301 | - | All | All | All |
| Operating System | Cisco | Spa 301 Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 301 Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 303 | - | All | All | All |
| Hardware | Cisco | Spa 303 | - | All | All | All |
| Operating System | Cisco | Spa 303 Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 303 Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 500ds | - | All | All | All |
| Hardware | Cisco | Spa 500ds | - | All | All | All |
| Operating System | Cisco | Spa 500ds Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 500ds Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 500s | - | All | All | All |
| Hardware | Cisco | Spa 500s | - | All | All | All |
| Operating System | Cisco | Spa 500s Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 500s Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 501g | - | All | All | All |
| Hardware | Cisco | Spa 501g | - | All | All | All |
| Operating System | Cisco | Spa 501g Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 501g Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 502g | - | All | All | All |
| Hardware | Cisco | Spa 502g | - | All | All | All |
| Operating System | Cisco | Spa 502g Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 502g Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 504g | - | All | All | All |
| Hardware | Cisco | Spa 504g | - | All | All | All |
| Operating System | Cisco | Spa 504g Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 504g Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 508g | - | All | All | All |
| Hardware | Cisco | Spa 508g | - | All | All | All |
| Operating System | Cisco | Spa 508g Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 508g Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 509g | - | All | All | All |
| Hardware | Cisco | Spa 509g | - | All | All | All |
| Operating System | Cisco | Spa 509g Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 509g Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 512g | - | All | All | All |
| Hardware | Cisco | Spa 512g | - | All | All | All |
| Operating System | Cisco | Spa 512g Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 512g Firmware | 7.6.2 | All | All | All |
| Hardware | Cisco | Spa 514g | - | All | All | All |
| Hardware | Cisco | Spa 514g | - | All | All | All |
| Operating System | Cisco | Spa 514g Firmware | 7.6.2 | All | All | All |
| Operating System | Cisco | Spa 514g Firmware | 7.6.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Cisco Products CVE-2017-12219 Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones Denial of Service Vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones Lets Remote Users Cause the Target System to Reload - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.