安全研究

安全漏洞
Cisco Small Business SPA300/SPA500 Series IP Phones 拒绝服务漏洞(CVE-2016-1469)

发布日期:2016-08-30
更新日期:2016-09-02

受影响系统:
Cisco Small Business SPA300 <  7.5.7(6)
Cisco Small Business SPA300
Cisco SPA500 Series IP Phones <  7.5.7(6)
描述:
BUGTRAQ  ID: 92706
CVE(CAN) ID: CVE-2016-1469

Cisco SPA300及SPA500是网络电话系列产品。

Cisco Small Business SPA300 Series IP Phones、Cisco Small Business SPA500 Series IP Phones、Cisco SPA51x IP Phones的HTTP框架存在安全漏洞。未经身份验证的远程攻击者可造成受影响设备拒绝服务。此漏洞源于未正确处理畸形的HTTP数据。

<*来源:Chris Watts
  
  链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-spa
*>

建议:
厂商补丁:

Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20160831-spa)以及相应补丁:
cisco-sa-20160831-spa:Cisco Small Business SPA3x/5x Series Denial of Service Vulnerability
链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160831-spa

浏览次数:2017
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障