VendorsCiscounified_ip_phone_9951all versions
Vulnerabilities

Cisco Unified IP Phone 9951

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2018-0332
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit this vulnerability by sending high volumes of SIP INVITE traffic to the targeted device. Successful exploitation could allow the attacker to cause a disruption of services on the targeted IP phone. Cisco Bug IDs: CSCve10064, CSCve14617, CSCve14638, CSCve14683, CSCve20812, CSCve20926, CSCve20945.
Published 2018-06-07 · Modified
7.5EPSS 0.034
CVE-2022-20817
Cisco IP Phone Duplicate Key Vulnerability
Published 2022-06-15 · Modified
7.4EPSS 0.012
CVE-2013-5526
Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.
Published 2013-10-10 · Modified
7.1EPSS 0.018
CVE-2013-6685
The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.
Published 2013-11-13 · Modified
6.6EPSS 0.003
CVE-2013-5533
The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.
Published 2013-10-11 · Modified
6.0EPSS 0.003
CVE-2014-0658
Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898.
Published 2014-01-10 · Modified
5.4EPSS 0.027
CVE-2020-3360
Cisco IP Phones Series 7800 and Series 8800 Call Log Information Disclosure Vulnerability
Published 2020-06-18 · Modified
5.3EPSS 0.013
CVE-2015-0600
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff) via crafted packets, aka Bug ID CSCuq12139.
Published 2015-02-07 · Modified
5.0EPSS 0.022
CVE-2013-5532
Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug ID CSCuh10343.
Published 2013-10-11 · Modified
5.0EPSS 0.021
CVE-2015-0602
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117.
Published 2015-02-07 · Modified
5.0EPSS 0.014
CVE-2015-0604
The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.
Published 2015-02-07 · Modified
5.0EPSS 0.014
CVE-2013-3426
The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810.
Published 2013-07-17 · Modified
5.0EPSS 0.012
CVE-2015-0601
Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790.
Published 2015-02-07 · Modified
4.6EPSS 0.003
CVE-2015-0603
Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier use weak permissions for unspecified files, which allows local users to cause a denial of service (persistent hang or reboot) by writing to a phone's filesystem, aka Bug ID CSCup90474.
Published 2015-02-07 · Modified
4.6EPSS 0.003