CVE-2003-1109

N/A Unknown
Published: December 31, 2003 Modified: April 16, 2026
View on NVD

Description

The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.cert.org/advisories/CA-2003-06.html
Source: cve@mitre.org
Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/528719
Source: cve@mitre.org
Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/6904
Source: cve@mitre.org
Patch
http://www.cert.org/advisories/CA-2003-06.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory US Government Resource
http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.kb.cert.org/vuls/id/528719
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/6904
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.securitytracker.com/id?1006143
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1006144
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1006145
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/11379
Source: af854a3a-2127-422b-91ae-364da2661108

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
24.7%
96th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

cisco