CVE-2019-1922
published 2019-07-06CVE-2019-1922: A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.32%
67.5th percentile
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ip_phone_8800_series_software | >= unspecified < 12.0(1)MN130 | 12.0(1)MN130 |
| cisco | ip_conference_phone_8832_firmware | — | — |
| cisco | ip_conference_phone_8832_firmware | — | — |
| cisco | ip_phone_7800_and_8800_series_session_initiation_protocol | — | — |
| cisco | ip_phone_8811_firmware | — | — |
| cisco | ip_phone_8811_firmware | — | — |
| cisco | ip_phone_8841_firmware | — | — |
| cisco | ip_phone_8841_firmware | — | — |
| cisco | ip_phone_8845_firmware | — | — |
| cisco | ip_phone_8845_firmware | — | — |
| cisco | ip_phone_8851_firmware | — | — |
| cisco | ip_phone_8851_firmware | — | — |
| cisco | ip_phone_8861_firmware | — | — |
| cisco | ip_phone_8861_firmware | — | — |
| cisco | ip_phone_8865_firmware | — | — |
| cisco | ip_phone_8865_firmware | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2019-07-03·CVSS 5.3
CVE-2019-1922 [MEDIUM] CWE-476 Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone.
The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps
Cisco
Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1922 Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
CVE-2019-1922: Cisco IP Phone 7800 and 8800 Series Session Initiation Protocol Denial of Service Vulnerability
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process. There are no
CVSS: 3.0
CWE: CWE-476, CWE-476
Bug IDs: CSCvc61672
GHSA
GHSA-996r-f8xw-6h6p: A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause
ghsa_unreviewed·2022-05-24
CVE-2019-1922 [HIGH] CWE-476 GHSA-996r-f8xw-6h6p: A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause
A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.
Kernel
btrfs: Don't submit any btree write bio if the fs has errors
kernel_security·2020-02-12
CVE-2019-19377 btrfs: Don't submit any btree write bio if the fs has errors
btrfs: Don't submit any btree write bio if the fs has errors
[BUG]
There is a fuzzed image which could cause KASAN report at unmount time.
BUG: KASAN: use-after-free in btrfs_queue_work+0x2c1/0x390
Read of size 8 at addr ffff888067cf6848 by task umount/1922
CPU: 0 PID: 1922 Comm: umount Tainted: G W 5.0.21 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014
Call Trace:
dump_stack+0x5b/0x8b
print_address_description+0x70/0x280
kasan_report+0x13a/0x19b
btrfs_queue_work+0x2c1/0x390
btrfs_wq_submit_bio+0x1cd/0x240
btree_submit_bio_hook+0x18c/0x2a0
submit_one_bio+0x1be/0x320
flush_write_bio.isra.41+0x2c/0x70
btree_write_cache_pages+0x3bb/0x7f0
do_writepages+0x5c/0x130
__writeback_single_inode+0xa3/0x9a0
writeback_single_inode+0x23d/0x390
write_inode_now+
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-06
Published