CVE-2003-1109 describes a denial-of-service vulnerability, potentially leading to arbitrary code execution, in the Session Initiation Protocol (SIP) implementation across various Cisco products, including IP Phone models 7940/7960, specific IOS versions, and Secure PIX firewall software. This vulnerability is triggered by crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite. With a CVSS score of 7.5, it represents a high-severity risk, allowing unauthenticated remote attackers to exploit it with low attack complexity, potentially impacting confidentiality, integrity, and availability. While the FAUCET Risk Score is high at 86/100, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(1\)xaCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(1\)xa:*:*:*:*:*:*:* | ||
12.2\(1\)xdCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(1\)xd:*:*:*:*:*:*:* | ||
12.2\(1\)xd1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(1\)xd1:*:*:*:*:*:*:* | ||
12.2\(1\)xd3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(1\)xd3:*:*:*:*:*:*:* | ||
12.2\(1\)xd4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(1\)xd4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.