A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient sanity checks on an internal data structure. An attacker could exploit this vulnerability by sending a sequence of malicious SIP messages to an affected device. An exploit could allow the attacker to cause a NULL pointer dereference, resulting in a crash of the iosd process. This triggers a reload of the device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
1000 Integrated Services Router
Subscribe
1100 Integrated Services Router
Subscribe
4000 Integrated Services Router
Subscribe
4221 Integrated Services Router
Subscribe
4321 Integrated Services Router
Subscribe
4331 Integrated Services Router
Subscribe
4351 Integrated Services Router
Subscribe
4431 Integrated Services Router
Subscribe
4451-x Integrated Services Router
Subscribe
Asr 1000
Subscribe
Asr 1001-hx
Subscribe
Asr 1001-x
Subscribe
Asr 1002-hx
Subscribe
Asr 1002-x
Subscribe
Cloud Services Router 1000v
Subscribe
Integrated Services Virtual Router
Subscribe
Ios Xe
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4245 | A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient sanity checks on an internal data structure. An attacker could exploit this vulnerability by sending a sequence of malicious SIP messages to an affected device. An exploit could allow the attacker to cause a NULL pointer dereference, resulting in a crash of the iosd process. This triggers a reload of the device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 19 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-19T18:55:23.215Z
Reserved: 2019-06-04T00:00:00
Link: CVE-2019-12654
Updated: 2024-08-04T23:24:39.173Z
Status : Modified
Published: 2019-09-25T21:15:10.717
Modified: 2024-11-21T04:23:16.343
Link: CVE-2019-12654
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD