Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-1763— Cisco IP Phone 8800 Series Authorization Bypass Vulnerability

EPSS 1.13% · P78
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-1763

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco IP Phone 8800 Series Authorization Bypass Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to critical services and cause a DoS condition. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series. Cisco IP Conference Phone 8831 is not affected.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
访问控制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco IP Phone 8800 Series Session Initiation Protocol软件访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IP Phone 8800 Series是美国思科(Cisco)公司的一款8800系列的IP电话。Session Initiation Protocol(SIP)Software是其中的一款会话发起协议软件。 Cisco IP Phone 8800 Series中的SIP软件的基于Web的管理界面存在访问控制错误漏洞,该漏洞源于程序在处理请求之前没有过滤URLs。远程攻击者可通过提交特制的URL利用该漏洞绕过授权,使用重要的服务功能并造成拒绝服务。以下产品受到影响:Cisco Wireless
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco Wireless IP Phone 8821 and 8821-EX unspecified ~ 11.0(5) -
CiscoCisco IP Conference Phone 8832 and the rest of the IP Phone 8800 Series unspecified ~ 12.5(1)SR1 -

II. Public POCs for CVE-2019-1763

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-1763

登录查看更多情报信息。

Same Patch Batch · Cisco · 2019-03-22 · 5 CVEs total

CVE-2019-1716Cisco IP Phone 7800 Series and 8800 Series Remote Code Execution Vulnerability
CVE-2019-1764Cisco IP Phone 8800 Series Cross-Site Request Forgery Vulnerability
CVE-2019-1765Cisco IP Phone 8800 Series Path Traversal Vulnerability
CVE-2019-1766Cisco IP Phone 8800 Series File Upload Denial of Service Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2019-1763

No comments yet


Leave a comment