CVE-2002-0882
The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2)…
Does this matter?
Lower severity and a low EPSS score (2.75%). Track it; it rarely justifies an emergency change on its own.
Description
The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
- EPSS
- 2.75% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- cisco/voip phone cp-7940 · cisco/skinny client control protocol software
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/273673
- http://www.cisco.com/warp/public/707/multiple-ip-phone-vulnerabilities-pub.shtmlVendor Advisory
- http://www.iss.net/security_center/static/9142.php
- http://www.iss.net/security_center/static/9143.php
- http://www.securityfocus.com/bid/4794Vendor Advisory
- http://www.securityfocus.com/bid/4798
- http://online.securityfocus.com/archive/1/273673
- http://www.cisco.com/warp/public/707/multiple-ip-phone-vulnerabilities-pub.shtmlVendor Advisory
- http://www.iss.net/security_center/static/9142.php
- http://www.iss.net/security_center/static/9143.php
- http://www.securityfocus.com/bid/4794Vendor Advisory
- http://www.securityfocus.com/bid/4798
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.