CVE-2020-3574
published 2020-11-06CVE-2020-3574: A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
7.94%
94.0th percentile
A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload. The vulnerability is due to insufficient TCP ingress packet rate limiting. An attacker could exploit this vulnerability by sending a high and sustained rate of crafted TCP traffic to the targeted device. A successful exploit could allow the attacker to impact operations of the phone or cause the phone to reload, leading to a denial of service (DoS) condition.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ip_phones_with_multiplatform_firmware | — | — |
| cisco | ip_dect_210_firmware | < 4.8.1 | 4.8.1 |
| cisco | ip_dect_6825_firmware | < 4.8.1 | 4.8.1 |
| cisco | ip_phone_8811_firmware | < 11.3.2 | 11.3.2 |
| cisco | ip_phone_8841_firmware | < 11.3.2 | 11.3.2 |
| cisco | ip_phone_8851_firmware | < 11.3.2 | 11.3.2 |
| cisco | ip_phone_8861_firmware | < 11.3.2 | 11.3.2 |
| cisco | ip_phone_tcp_packet_flood | — | — |
| cisco | unified_ip_conference_phone_8831_firmware | — | — |
| cisco | webex_room_phone_firmware | < 1.2.0 | 1.2.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gp65-v6f3-j928: A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to st
ghsa_unreviewed·2022-05-24
CVE-2020-3574 [HIGH] GHSA-gp65-v6f3-j928: A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to st
A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload. The vulnerability is due to insufficient TCP ingress packet rate limiting. An attacker could exploit this vulnerability by sending a high and sustained rate of crafted TCP traffic to the targeted device. A successful exploit could allow the attacker to impact operations of the phone or cause the phone to reload, leading to a denial of service (DoS) condition.
Cisco
Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability
vendor_cisco·2020-11-04·CVSS 7.5
CVE-2020-3574 [HIGH] CWE-371 Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability
Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability
A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload.
The vulnerability is due to insufficient TCP ingress packet rate limiting. An attacker could exploit this vulnerability by sending a high and sustained rate of crafted TCP traffic to the targeted device. A successful exploit could allow the attacker to impact operations of the phone or cause the phone to reload, leading to a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is
Cisco
Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3574 Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability
CVE-2020-3574: Cisco IP Phone TCP Packet Flood Denial of Service Vulnerability
A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload. The vulnerability is due to insufficient TCP ingress packet rate limiting. An attacker could exploit this vulnerability by sending a high and sustained rate of crafted TCP traffic to the targeted device. A successful exploit could allow the attacker to impact operations of the phone or cause the phone to reload, leading to a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-371, CWE-371
Bug IDs: CSCvs66
Suricata
ET EXPLOIT Access To mm-forms-community upload dir (Inbound)
suricata·2012-09-22
CVE-2012-3574 ET EXPLOIT Access To mm-forms-community upload dir (Inbound)
ET EXPLOIT Access To mm-forms-community upload dir (Inbound)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Access To mm-forms-community upload dir (Inbound)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/mm-forms-community/upload/temp/"; fast_pattern; reference:url,www.exploit-db.com/exploits/18997/; reference:cve,2012-3574; classtype:trojan-activity; sid:2015727; rev:4; metadata:created_at 2012_09_22, cve CVE_2012_3574, signature_severity Major, updated_at 2020_09_01;)
Suricata
ET EXPLOIT Access To mm-forms-community upload dir (Outbound)
suricata·2012-09-22
CVE-2012-3574 ET EXPLOIT Access To mm-forms-community upload dir (Outbound)
ET EXPLOIT Access To mm-forms-community upload dir (Outbound)
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT Access To mm-forms-community upload dir (Outbound)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/wp-content/plugins/mm-forms-community/upload/temp/"; fast_pattern; reference:url,www.exploit-db.com/exploits/18997/; reference:cve,2012-3574; classtype:trojan-activity; sid:2015726; rev:4; metadata:created_at 2012_09_22, cve CVE_2012_3574, signature_severity Major, updated_at 2020_09_01;)
No public exploits indexed.
No writeups or analysis indexed.
2020-11-06
Published