Vulnerabilities > CVE-2002-0882 - Denial Of Service vulnerability in Cisco products

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
cisco
nessus

Summary

The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.

Nessus

NASL familyCISCO
NASL idCISCO_VOIP_DOS.NASL
descriptionThe remote host appears to be a Cisco IP phone. It was possible to reboot this device by requesting : http://<phone-ip>/StreamingStatistics?120000 This device likely has other vulnerabilities that Nessus has not checked for.
last seen2020-06-01
modified2020-06-02
plugin id11013
published2002-06-05
reporterThis script is Copyright (C) 2002-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11013
titleCisco VoIP Phone Multiple Script Malformed Request DoS