10
CVSSv2

CVE-2008-0528

Published: 15/02/2008 Updated: 08/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote malicious users to execute arbitrary code via a SIP message with crafted MIME data.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco skinny client control protocol (sccp) firmware

cisco session initiation protocol (sip) firmware

Github Repositories

Proof of concept attacks for my zero days in Cisco VoIP phones, and other shenanigans.

Cisco_7940G_7960G_remote_exploits Proof of concept attacks for my zero days in Cisco VoIP phones, and other shenanigans The future home of a lot of POCs The POCs are done, I'm just writing things up and requesting CVEs Already posted: SIP OPTIONS packet overflow Sipp POC of my zero day Affected SIP FW versions: 86 (and older, presumably) Confirmed vulnerable versions