CVE-2019-12646
Summary
| CVE | CVE-2019-12646 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-25 20:15:00 UTC |
| Updated | 2023-05-22 18:57:00 UTC |
| Description | A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected device. An attacker could exploit this vulnerability by using UDP port 5060 to send crafted SIP packets through an affected device that is performing NAT for SIP packets. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition. |
Risk And Classification
Problem Types: CWE-665
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 1100-4p | - | All | All | All |
| Hardware | Cisco | 1100-4p | - | All | All | All |
| Hardware | Cisco | 1100-8p | - | All | All | All |
| Hardware | Cisco | 1100-8p | - | All | All | All |
| Hardware | Cisco | 1101-4p | - | All | All | All |
| Hardware | Cisco | 1101-4p | - | All | All | All |
| Hardware | Cisco | 1109-2p | - | All | All | All |
| Hardware | Cisco | 1109-2p | - | All | All | All |
| Hardware | Cisco | 1109-4p | - | All | All | All |
| Hardware | Cisco | 1109-4p | - | All | All | All |
| Hardware | Cisco | 1111x-8p | - | All | All | All |
| Hardware | Cisco | 1111x-8p | - | All | All | All |
| Hardware | Cisco | 4221 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4331 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | Csr 1000v | - | All | All | All |
| Hardware | Cisco | Csr 1000v | - | All | All | All |
| Hardware | Cisco | Encs 5100 | - | All | All | All |
| Hardware | Cisco | Encs 5100 | - | All | All | All |
| Hardware | Cisco | Encs 5400 | - | All | All | All |
| Hardware | Cisco | Encs 5400 | - | All | All | All |
| Operating System | Cisco | Ios Xe | 15.4(3)s | All | All | All |
| Operating System | Cisco | Ios Xe | 15.4\(3\)s | All | All | All |
| Operating System | Cisco | Ios Xe | 15.5(3)s | All | All | All |
| Operating System | Cisco | Ios Xe | 15.5\(3\)s | All | All | All |
| Operating System | Cisco | Ios Xe | 15.6(1)s | All | All | All |
| Operating System | Cisco | Ios Xe | 15.6\(1\)s | All | All | All |
| Operating System | Cisco | Ios Xe | 16.10.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.11.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.12.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.3.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.4.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.5.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.9.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 15.4\(3\)s | All | All | All |
| Operating System | Cisco | Ios Xe | 15.5\(3\)s | All | All | All |
| Operating System | Cisco | Ios Xe | 15.6\(1\)s | All | All | All |
| Operating System | Cisco | Ios Xe | 16.10.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.11.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.12.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.3.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.4.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.5.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.9.1 | All | All | All |
| Hardware | Cisco | Isrv | - | All | All | All |
| Hardware | Cisco | Isrv | - | All | All | All |
| Hardware | Cisco | Isr 4221 | - | All | All | All |
| Hardware | Cisco | Isr 4221 | - | All | All | All |
| Hardware | Cisco | Isr 4331 | - | All | All | All |
| Hardware | Cisco | Isr 4331 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.