ID

VAR-201505-0193


CVE

CVE-2015-0751


TITLE

Cisco IP Phone 7861 Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-002877

DESCRIPTION

Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800. Vendors have confirmed this vulnerability Bug ID CSCus81800 It is released as.Denial of service operation via a packet crafted by a third party (DoS) There is a possibility of being put into a state. The Cisco IP Phone 7861 is an IP phone that can communicate with wideband audio and video. Allowing an unauthenticated remote attacker to exploit this vulnerability could cause the device to reboot, resulting in a denial of service. This issue is tracked by Cisco Bug ID CSCus81800

Trust: 2.52

sources: NVD: CVE-2015-0751 // JVNDB: JVNDB-2015-002877 // CNVD: CNVD-2015-03480 // BID: 74834 // VULHUB: VHN-78697

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-03480

AFFECTED PRODUCTS

vendor:ciscomodel:unified communications managerscope:eqversion:10.3\(1\)

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:10.3(1)

Trust: 1.1

vendor:ciscomodel:ip phone 7861scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phonescope:eqversion:7861

Trust: 0.6

vendor:ciscomodel:ip phonescope:eqversion:78610

Trust: 0.3

sources: CNVD: CNVD-2015-03480 // BID: 74834 // JVNDB: JVNDB-2015-002877 // CNNVD: CNNVD-201505-587 // NVD: CVE-2015-0751

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0751
value: HIGH

Trust: 1.0

NVD: CVE-2015-0751
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-03480
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201505-587
value: HIGH

Trust: 0.6

VULHUB: VHN-78697
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-0751
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-03480
severity: MEDIUM
baseScore: 5.4
vectorString: AV:N/AC:H/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 4.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-78697
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-03480 // VULHUB: VHN-78697 // JVNDB: JVNDB-2015-002877 // CNNVD: CNNVD-201505-587 // NVD: CVE-2015-0751

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

problemtype:CWE-399

Trust: 1.1

sources: VULHUB: VHN-78697 // JVNDB: JVNDB-2015-002877 // NVD: CVE-2015-0751

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201505-587

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201505-587

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002877

PATCH

title:39011url:http://tools.cisco.com/security/center/viewAlert.x?alertId=39011

Trust: 0.8

title:Patch for Cisco IP Phone 7861 Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/59068

Trust: 0.6

sources: CNVD: CNVD-2015-03480 // JVNDB: JVNDB-2015-002877

EXTERNAL IDS

db:NVDid:CVE-2015-0751

Trust: 3.4

db:SECTRACKid:1032407

Trust: 1.1

db:BIDid:74834

Trust: 1.0

db:JVNDBid:JVNDB-2015-002877

Trust: 0.8

db:CNNVDid:CNNVD-201505-587

Trust: 0.7

db:CNVDid:CNVD-2015-03480

Trust: 0.6

db:VULHUBid:VHN-78697

Trust: 0.1

sources: CNVD: CNVD-2015-03480 // VULHUB: VHN-78697 // BID: 74834 // JVNDB: JVNDB-2015-002877 // CNNVD: CNNVD-201505-587 // NVD: CVE-2015-0751

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=39011

Trust: 2.6

url:http://www.securitytracker.com/id/1032407

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0751

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0751

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2015-03480 // VULHUB: VHN-78697 // BID: 74834 // JVNDB: JVNDB-2015-002877 // CNNVD: CNNVD-201505-587 // NVD: CVE-2015-0751

CREDITS

Cisco

Trust: 0.3

sources: BID: 74834

SOURCES

db:CNVDid:CNVD-2015-03480
db:VULHUBid:VHN-78697
db:BIDid:74834
db:JVNDBid:JVNDB-2015-002877
db:CNNVDid:CNNVD-201505-587
db:NVDid:CVE-2015-0751

LAST UPDATE DATE

2024-11-23T22:42:28.839000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-03480date:2015-06-01T00:00:00
db:VULHUBid:VHN-78697date:2017-01-04T00:00:00
db:BIDid:74834date:2015-05-26T00:00:00
db:JVNDBid:JVNDB-2015-002877date:2015-06-03T00:00:00
db:CNNVDid:CNNVD-201505-587date:2015-06-05T00:00:00
db:NVDid:CVE-2015-0751date:2024-11-21T02:23:39.100

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-03480date:2015-05-30T00:00:00
db:VULHUBid:VHN-78697date:2015-05-29T00:00:00
db:BIDid:74834date:2015-05-26T00:00:00
db:JVNDBid:JVNDB-2015-002877date:2015-06-03T00:00:00
db:CNNVDid:CNNVD-201505-587date:2015-05-29T00:00:00
db:NVDid:CVE-2015-0751date:2015-05-29T15:59:05.390