CVE-2008-3802
published 2008-09-26CVE-2008-3802: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote…
high7.1CVSS 3.1
AVNACMAuNCNINAC
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (device reload) via unspecified valid SIP messages, aka Cisco bug ID CSCsk42759, a different vulnerability than CVE-2008-3800 and CVE-2008-3801.
Affected
94 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-w52f-gfhm-992j: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-02·CVSS 7.1
CVE-2008-3800 [HIGH] GHSA-w52f-gfhm-992j: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsu38644, a different vulnerability than CVE-2008-3801 and CVE-2008-3802.
GHSA
GHSA-7r4m-p2w9-fj4x: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-02·CVSS 7.1
CVE-2008-3802 [HIGH] GHSA-7r4m-p2w9-fj4x: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (device reload) via unspecified valid SIP messages, aka Cisco bug ID CSCsk42759, a different vulnerability than CVE-2008-3800 and CVE-2008-3801.
GHSA
GHSA-9gcq-w2xv-xvf8: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-02·CVSS 7.1
CVE-2008-3801 [HIGH] GHSA-9gcq-w2xv-xvf8: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsm46064, a different vulnerability than CVE-2008-3800 and CVE-2008-3802.
Cisco
Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco·2008-09-24·CVSS 7.8
CVE-2008-3799 [HIGH] CWE-399 Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities
Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP)
implementation in Cisco IOS that can be exploited remotely to trigger a memory
leak or to cause a reload of the IOS device.
Cisco has released software updates that address these vulnerabilities. Fixed Cisco IOS software listed in the Software Versions and
Fixes section contains fixes for all vulnerabilities addressed in this
advisory.
There are no workarounds available to mitigate the effects of any of
the vulnerabilities apart from disabling the protocol or feature itself, if
administrators do not require the Cisco IOS device to provide voice over IP
services.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/
Cisco
Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco
CVE-2008-3802 Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities
CVE-2008-3802: Multiple Cisco IOS Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS that can be exploited remotely to trigger a memory leak or to cause a reload of the IOS device. Cisco has released software updates that address these vulnerabilities. Fixed Cisco IOS software listed in the Software Versions and Fixes section contains fixes for all vulnerabilities addressed in this advisory. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCse56800, CSCsg91306, CSCsk42759, CSCsb25337, CSCse56800
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/31990http://www.cisco.com/en/US/products/products_security_advisory09186a0080a01562.shtmlhttp://www.securitytracker.com/id?1020939http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5889http://secunia.com/advisories/31990http://www.cisco.com/en/US/products/products_security_advisory09186a0080a01562.shtmlhttp://www.securitytracker.com/id?1020939http://www.vupen.com/english/advisories/2008/2670https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5889
2008-09-26
Published