ID

VAR-201907-0867


CVE

CVE-2019-1922


TITLE

Cisco IP Phone 7800 and 8800 In the series NULL Pointer dereference vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-006422

DESCRIPTION

A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process. SIP IP Phone Software is one set of IP phone software. This issue is being tracked by Cisco Bug IDs CSCvc61672

Trust: 2.52

sources: NVD: CVE-2019-1922 // JVNDB: JVNDB-2019-006422 // CNVD: CNVD-2020-51806 // BID: 109046 // VULHUB: VHN-151644

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-51806

AFFECTED PRODUCTS

vendor:ciscomodel:ip phone 8845scope:eqversion:11.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:eqversion:12.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7861scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:ip conference phone 7832scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:eqversion:11.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851scope:eqversion:11.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7811scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:eqversion:12.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:eqversion:12.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7841scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:ip conference phone 8832scope:eqversion:11.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8841scope:eqversion:11.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8845scope:eqversion:12.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 7821scope:eqversion: -

Trust: 1.0

vendor:ciscomodel:ip phone 8865scope:eqversion:11.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8811scope:eqversion:11.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8861scope:eqversion:12.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip phone 8851scope:eqversion:12.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip conference phone 8832scope:eqversion:12.5\(1\)

Trust: 1.0

vendor:ciscomodel:ip conference phone 7832scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip conference phone 8832scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 7811scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 7821scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 7841scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 7861scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 8811scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 8841scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 8845scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone 8851scope: - version: -

Trust: 0.8

vendor:ciscomodel:ip phone seriesscope:eqversion:8800

Trust: 0.6

vendor:ciscomodel:ip phone series nonescope:eqversion:7800

Trust: 0.6

vendor:ciscomodel:unified ip conference phone for third-party call controlscope:eqversion:88310

Trust: 0.3

vendor:ciscomodel:unified ip conference phonescope:eqversion:88310

Trust: 0.3

vendor:ciscomodel:ip phone with multiplatformscope:eqversion:88650

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:88650

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:88610

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:88510

Trust: 0.3

vendor:ciscomodel:ip phone with multiplatformscope:eqversion:88450

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:88450

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:88410

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:88110

Trust: 0.3

vendor:ciscomodel:ip phone series vpn featurescope:eqversion:8800??0

Trust: 0.3

vendor:ciscomodel:ip phone seriesscope:eqversion:88000

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:78610

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:78410

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:78210

Trust: 0.3

vendor:ciscomodel:ip phonescope:eqversion:78110

Trust: 0.3

vendor:ciscomodel:ip phone series with multiplatformscope:eqversion:78000

Trust: 0.3

vendor:ciscomodel:ip conference phonescope:eqversion:88320

Trust: 0.3

vendor:ciscomodel:ip conference phonescope:eqversion:78320

Trust: 0.3

sources: CNVD: CNVD-2020-51806 // BID: 109046 // JVNDB: JVNDB-2019-006422 // NVD: CVE-2019-1922

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-1922
value: HIGH

Trust: 1.0

ykramarz@cisco.com: CVE-2019-1922
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-1922
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-51806
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201907-226
value: HIGH

Trust: 0.6

VULHUB: VHN-151644
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-1922
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2020-51806
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-151644
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-1922
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

ykramarz@cisco.com: CVE-2019-1922
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 1.6
impactScore: 3.6
version: 3.0

Trust: 1.0

sources: CNVD: CNVD-2020-51806 // VULHUB: VHN-151644 // JVNDB: JVNDB-2019-006422 // CNNVD: CNNVD-201907-226 // NVD: CVE-2019-1922 // NVD: CVE-2019-1922

PROBLEMTYPE DATA

problemtype:CWE-476

Trust: 1.9

sources: VULHUB: VHN-151644 // JVNDB: JVNDB-2019-006422 // NVD: CVE-2019-1922

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201907-226

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-201907-226

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-006422

PATCH

title:cisco-sa-20190703-ip-phone-sip-dosurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-ip-phone-sip-dos

Trust: 0.8

title:Patch for Denial of Service Vulnerability in Cisco IP Phone 7800 and 8800 Seriesurl:https://www.cnvd.org.cn/patchInfo/show/167013

Trust: 0.6

title:Cisco IP Phone 8800 Series and Cisco IP Phone 7800 Series Fixes for code issue vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=94415

Trust: 0.6

sources: CNVD: CNVD-2020-51806 // JVNDB: JVNDB-2019-006422 // CNNVD: CNNVD-201907-226

EXTERNAL IDS

db:NVDid:CVE-2019-1922

Trust: 3.4

db:BIDid:109046

Trust: 1.0

db:JVNDBid:JVNDB-2019-006422

Trust: 0.8

db:CNNVDid:CNNVD-201907-226

Trust: 0.7

db:CNVDid:CNVD-2020-51806

Trust: 0.6

db:AUSCERTid:ESB-2019.2443

Trust: 0.6

db:VULHUBid:VHN-151644

Trust: 0.1

sources: CNVD: CNVD-2020-51806 // VULHUB: VHN-151644 // BID: 109046 // JVNDB: JVNDB-2019-006422 // CNNVD: CNNVD-201907-226 // NVD: CVE-2019-1922

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2019-1922

Trust: 2.0

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190703-ip-phone-sip-dos

Trust: 2.0

url:http://www.cisco.com/

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-1922

Trust: 0.8

url:https://vigilance.fr/vulnerability/cisco-ip-phone-7800-8800-denial-of-service-via-sip-29690

Trust: 0.6

url:https://www.securityfocus.com/bid/109046

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.2443/

Trust: 0.6

sources: CNVD: CNVD-2020-51806 // VULHUB: VHN-151644 // BID: 109046 // JVNDB: JVNDB-2019-006422 // CNNVD: CNNVD-201907-226 // NVD: CVE-2019-1922

CREDITS

Thomas Sabono of xen1thLabs.

Trust: 0.9

sources: BID: 109046 // CNNVD: CNNVD-201907-226

SOURCES

db:CNVDid:CNVD-2020-51806
db:VULHUBid:VHN-151644
db:BIDid:109046
db:JVNDBid:JVNDB-2019-006422
db:CNNVDid:CNNVD-201907-226
db:NVDid:CVE-2019-1922

LAST UPDATE DATE

2024-11-23T22:06:07.776000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-51806date:2020-09-14T00:00:00
db:VULHUBid:VHN-151644date:2019-10-09T00:00:00
db:BIDid:109046date:2019-07-03T00:00:00
db:JVNDBid:JVNDB-2019-006422date:2019-07-19T00:00:00
db:CNNVDid:CNNVD-201907-226date:2019-07-18T00:00:00
db:NVDid:CVE-2019-1922date:2024-11-21T04:37:41.573

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-51806date:2019-09-07T00:00:00
db:VULHUBid:VHN-151644date:2019-07-06T00:00:00
db:BIDid:109046date:2019-07-03T00:00:00
db:JVNDBid:JVNDB-2019-006422date:2019-07-19T00:00:00
db:CNNVDid:CNNVD-201907-226date:2019-07-03T00:00:00
db:NVDid:CVE-2019-1922date:2019-07-06T02:15:11.793