Vulnerabilities > CVE-2003-1109 - Unspecified vulnerability in Cisco products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN cisco
nessus
Summary
The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
Vulnerable Configurations
Nessus
NASL family CISCO NASL id CISCO-SA-20030221-PROTOSHTTP.NASL description Multiple Cisco products contain vulnerabilities in the processing of Session Initiation Protocol (SIP) INVITE messages. These vulnerabilities were identified by the University of Oulu Secure Programming Group (OUSPG) last seen 2019-10-28 modified 2010-09-01 plugin id 48969 published 2010-09-01 reporter This script is (C) 2010-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/48969 title Multiple Product Vulnerabilities Found by PROTOS SIP Test Suite - Cisco Systems NASL family CISCO NASL id CSCDZ39284.NASL description It is possible to make the remote IOS crash when sending it malformed SIP packets. These vulnerabilities are documented as CISCO bug id CSCdz39284 and CSCdz41124. last seen 2020-06-01 modified 2020-06-02 plugin id 11380 published 2003-03-14 reporter This script is (C) 2003-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/11380 title Cisco SIP Crafted INVITE Message Handling DoS (CSCdz39284, CSCdz41124)
References
- http://www.cert.org/advisories/CA-2003-06.html
- http://www.cert.org/advisories/CA-2003-06.html
- http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml
- http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/
- http://www.kb.cert.org/vuls/id/528719
- http://www.kb.cert.org/vuls/id/528719
- http://www.securityfocus.com/bid/6904
- http://www.securityfocus.com/bid/6904
- http://www.securitytracker.com/id?1006143
- http://www.securitytracker.com/id?1006143
- http://www.securitytracker.com/id?1006144
- http://www.securitytracker.com/id?1006144
- http://www.securitytracker.com/id?1006145
- http://www.securitytracker.com/id?1006145
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11379
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11379