Tech Analysis research archive

Tech Analysis discovers denial of service vulnerability in Cisco Small Business SPA3x/5x Series IP phones, CVE-2016-1469

Originally published on techanalysis.com.au by Tech Analysis on under the title "Discovered a Denial of Service Vulnerability in Cisco Small Business SPA3x/5x Series IP Phones. CVE-2016-1469"; first archived by the Internet Archive on . This page is a summary written to preserve the address and the record, not the original article text.

Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.

What was reported

On 31 August 2016 Cisco published an advisory for a denial of service vulnerability in the HTTP framework of its Small Business SPA300 Series, SPA500 Series and SPA51x IP phones running software release 7.5.7(6) or earlier, assigned CVE-2016-1469. In Cisco's words, an unauthenticated, remote attacker could cause a denial of service condition on an affected phone by sending a series of malformed HTTP requests. Cisco gave it a CVSS v2 base score of 7.8 and no workaround was available.

Tech Analysis announced the finding on this page on 1 September 2016.

Primary sources

Attribution

Cisco's advisory states: "Cisco would like to thank security researcher Chris Watts for discovering and reporting this vulnerability." The advisory names the researcher without an organisation; the original Tech Analysis announcement connects it to Tech Analysis.

See the full research index for all public vulnerability records credited to Chris Watts.