以下是该漏洞描述的中文翻译: Cisco 桌面电话 9800 系列、Cisco IP 电话 7800 和 8800 系列,以及 Cisco 视频电话 8875,如果运行 Cisco 会话初始协议(SIP)软件,可能存在一个漏洞,可能允许未认证的远程攻击者导致受影响设备发生拒绝服务(DoS)状况。 该漏洞源于受影响设备在处理 HTTP 数据包时的内存管理不当。攻击者可以通过向设备发送持续的特制 HTTP 数据包流来利用此漏洞。成功利用该漏洞将使受影响设备持续消耗内存,从而导致拒绝服务状况。从该状况恢复需要手动重启设备
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Session Initiation Protocol (SIP) Software | 12.1(1)SR1 |
affected |
11.5(1) |
affected | ||
10.3(2) |
affected | ||
10.2(2) |
affected | ||
10.3(1) |
affected | ||
10.3(1)SR4 |
affected | ||
11.0(1) |
affected | ||
10.4(1)SR2 3rd Party |
affected | ||
| … +102 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Session Initiation Protocol (SIP) Software | 12.1(1)SR1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20279 | 9.8 CRITICAL | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20274 | 9.8 CRITICAL | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20212 | 9.8 CRITICAL | Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Co |
| CVE-2026-20280 | 8.8 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20278 | 8.8 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20275 | 8.8 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20276 | 8.6 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20277 | 8.2 HIGH | Cisco IOS XR Software Security Hardening Release: September 2026 |
| CVE-2026-20355 | 5.9 MEDIUM | Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty |
| CVE-2026-20354 | 5.9 MEDIUM | Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty |
No comments yet