>> Cisco IOS Voice Service Session Initiated Protocol Denial of Service Vulnerability
Title : Cisco IOS Voice Service Session Initiated Protocol Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-0428 CVE ID : CVE-2007-0648
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-31
Technical Description
A vulnerability has been identified in Cisco IOS, which could be exploited by remote attackers to cause a denial of service. This issue is due to an error when handling malformed data sent to port 5060 on a device which supports voice services and is not configured for Session Initiated Protocol (SIP), which could be exploited by unauthenticated remote attackers to crash or reload an affected device, creating a denial of service condition.