CVE-2017-12259 describes a denial-of-service vulnerability in Cisco Small Business SPA51x Series IP Phones running firmware 7.6.2SR1 or earlier, caused by improper handling of malformed Session Initiation Protocol (SIP) messages. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated, remote attacker to render an affected device unresponsive, requiring a manual restart. While there is no known public exploit code or active exploitation, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:small_business_ip_phone_firmware:*:sr1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.