CVE-2017-12260
Summary
| CVE | CVE-2017-12260 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-19 08:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper handling of SIP request messages by an affected device. An attacker could exploit this vulnerability by using formatted specifiers in a SIP payload that is sent to an affected device. A successful exploit could allow the attacker to cause the affected device to become unresponsive, resulting in a DoS condition that persists until the device is restarted manually. This vulnerability affects Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones that are running firmware release 7.6.2SR1 or earlier. Cisco Bug IDs: CSCvc63986. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-119 | CWE-119 CWE-119
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Spa 501g | - | All | All | All |
| Operating System | Cisco | Spa 501g Firmware | All | sr1 | All | All |
| Hardware | Cisco | Spa 502g | - | All | All | All |
| Operating System | Cisco | Spa 502g Firmware | All | sr1 | All | All |
| Hardware | Cisco | Spa 504g | - | All | All | All |
| Operating System | Cisco | Spa 504g Firmware | All | sr1 | All | All |
| Hardware | Cisco | Spa 508g | - | All | All | All |
| Operating System | Cisco | Spa 508g Firmware | All | sr1 | All | All |
| Hardware | Cisco | Spa 509g | - | All | All | All |
| Operating System | Cisco | Spa 509g Firmware | All | sr1 | All | All |
| Hardware | Cisco | Spa 512g | - | All | All | All |
| Operating System | Cisco | Spa 512g Firmware | All | sr1 | All | All |
| Hardware | Cisco | Spa 514g | - | All | All | All |
| Operating System | Cisco | Spa 514g Firmware | All | sr1 | All | All |
| Hardware | Cisco | Spa 525g | - | All | All | All |
| Operating System | Cisco | Spa 525g Firmware | All | sr1 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco Small Business SPA50x SPA51x And SPA52x Series IP Phones | affected Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones SIP Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Small Business SPA50x/SPA51x/SPA52x Series IP Phones SIP Processing Flaw Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.