ID

VAR-201706-0578


CVE

CVE-2017-6656


TITLE

Cisco IP Phone 8800 Service disruption on devices (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2017-005141

DESCRIPTION

A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to the SIP process unexpectedly restarting. All active phone calls are dropped as the SIP process restarts. More Information: CSCvc29353. Known Affected Releases: 11.0(0.1). Known Fixed Releases: 11.0(0)MP2.153 11.0(0)MP2.62. Vendors have confirmed this vulnerability CSCvc29353 It is released as.Remote attacker could disrupt service operation (DoS) There is a possibility of being put into a state. The Cisco IP Phone 8800 Series is a telephone product that provides video and VoIP communication capabilities at Cisco. This issue is tracked by Cisco Bug ID CSCvc29353

Trust: 2.52

sources: NVD: CVE-2017-6656 // JVNDB: JVNDB-2017-005141 // CNVD: CNVD-2017-13761 // BID: 98996 // VULHUB: VHN-114859

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-13761

AFFECTED PRODUCTS

vendor:ciscomodel:ip phone 8800 seriesscope:eqversion:11.0\(0.1\)

Trust: 1.6

vendor:ciscomodel:ip phone seriesscope:eqversion:880011.0(0.1)

Trust: 0.9

vendor:ciscomodel:ip phone 8800 seriesscope:eqversion:11.0(0.1)

Trust: 0.8

vendor:ciscomodel:ip phone series 11.0 mp2.62scope:neversion:8800

Trust: 0.3

vendor:ciscomodel:ip phone series 11.0 mp2.153scope:neversion:8800

Trust: 0.3

sources: CNVD: CNVD-2017-13761 // BID: 98996 // JVNDB: JVNDB-2017-005141 // CNNVD: CNNVD-201706-434 // NVD: CVE-2017-6656

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6656
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-6656
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-13761
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201706-434
value: MEDIUM

Trust: 0.6

VULHUB: VHN-114859
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-6656
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-13761
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-114859
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6656
baseSeverity: MEDIUM
baseScore: 5.9
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-13761 // VULHUB: VHN-114859 // JVNDB: JVNDB-2017-005141 // CNNVD: CNNVD-201706-434 // NVD: CVE-2017-6656

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-114859 // JVNDB: JVNDB-2017-005141 // NVD: CVE-2017-6656

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201706-434

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201706-434

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-005141

PATCH

title:cisco-sa-20170607-sipurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-sip

Trust: 0.8

title:Patch for CiscoIPPhone8800Series Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/97806

Trust: 0.6

title:Cisco IP Phone 8800 Series Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=70880

Trust: 0.6

sources: CNVD: CNVD-2017-13761 // JVNDB: JVNDB-2017-005141 // CNNVD: CNNVD-201706-434

EXTERNAL IDS

db:NVDid:CVE-2017-6656

Trust: 3.4

db:BIDid:98996

Trust: 2.6

db:SECTRACKid:1038636

Trust: 1.7

db:JVNDBid:JVNDB-2017-005141

Trust: 0.8

db:CNNVDid:CNNVD-201706-434

Trust: 0.7

db:CNVDid:CNVD-2017-13761

Trust: 0.6

db:VULHUBid:VHN-114859

Trust: 0.1

sources: CNVD: CNVD-2017-13761 // VULHUB: VHN-114859 // BID: 98996 // JVNDB: JVNDB-2017-005141 // CNNVD: CNNVD-201706-434 // NVD: CVE-2017-6656

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170607-sip

Trust: 2.0

url:http://www.securityfocus.com/bid/98996

Trust: 1.7

url:http://www.securitytracker.com/id/1038636

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6656

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6656

Trust: 0.8

url:http://securitytracker.com/id/1038636

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2017-13761 // VULHUB: VHN-114859 // BID: 98996 // JVNDB: JVNDB-2017-005141 // CNNVD: CNNVD-201706-434 // NVD: CVE-2017-6656

CREDITS

Cisco

Trust: 0.9

sources: BID: 98996 // CNNVD: CNNVD-201706-434

SOURCES

db:CNVDid:CNVD-2017-13761
db:VULHUBid:VHN-114859
db:BIDid:98996
db:JVNDBid:JVNDB-2017-005141
db:CNNVDid:CNNVD-201706-434
db:NVDid:CVE-2017-6656

LAST UPDATE DATE

2025-04-20T23:40:04.545000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-13761date:2017-07-11T00:00:00
db:VULHUBid:VHN-114859date:2017-07-08T00:00:00
db:BIDid:98996date:2017-06-07T00:00:00
db:JVNDBid:JVNDB-2017-005141date:2017-07-19T00:00:00
db:CNNVDid:CNNVD-201706-434date:2017-06-14T00:00:00
db:NVDid:CVE-2017-6656date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-13761date:2017-07-11T00:00:00
db:VULHUBid:VHN-114859date:2017-06-13T00:00:00
db:BIDid:98996date:2017-06-07T00:00:00
db:JVNDBid:JVNDB-2017-005141date:2017-07-19T00:00:00
db:CNNVDid:CNNVD-201706-434date:2017-06-14T00:00:00
db:NVDid:CVE-2017-6656date:2017-06-13T06:29:00.863