CVE-2016-1469 describes a denial-of-service vulnerability in the HTTP framework of Cisco SPA300, SPA500, and SPA51x series IP phones. Remote unauthenticated attackers can exploit this flaw by sending a series of malformed HTTP requests, leading to a device outage. With a CVSS v3 score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with no user interaction required, resulting in high availability impact. There is no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei available. Despite limited community discussion and media coverage, the potential for a denial of service makes this a notable concern for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.5.7\(6\)CPE matchmatch criteria | cpe:2.3:o:cisco:spa300_firmware:*:*:*:*:*:*:*:* | ||
<= 7.5.7\(6\)CPE matchmatch criteria | cpe:2.3:o:cisco:spa500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.