Tech Analysis research archive
Tech Analysis discovers denial of service vulnerability in Cisco Small Business SPA3x/5x Series IP phones, CVE-2016-1469
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 31 August 2016 Cisco published an advisory for a denial of service vulnerability in the HTTP framework of its Small Business SPA300 Series, SPA500 Series and SPA51x IP phones running software release 7.5.7(6) or earlier, assigned CVE-2016-1469. In Cisco's words, an unauthenticated, remote attacker could cause a denial of service condition on an affected phone by sending a series of malformed HTTP requests. Cisco gave it a CVSS v2 base score of 7.8 and no workaround was available.
Tech Analysis announced the finding on this page on 1 September 2016.
Primary sources
- Cisco: Cisco Small Business SPA3x/5x Series Denial of Service Vulnerability (first published 31 August 2016)
- CVE-2016-1469 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
Attribution
Cisco's advisory states: "Cisco would like to thank security researcher Chris Watts for discovering and reporting this vulnerability." The advisory names the researcher without an organisation; the original Tech Analysis announcement connects it to Tech Analysis.
See the full research index for all public vulnerability records credited to Chris Watts.