CVE-2017-12260 is a denial-of-service vulnerability affecting Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones running firmware 7.6.2SR1 or earlier, stemming from improper handling of SIP request messages. An unauthenticated, remote attacker can exploit this by sending specially crafted SIP payloads with formatted specifiers, causing the device to become unresponsive until a manual restart. Rated 7.5 HIGH on CVSS, it requires no user interaction and has a low attack complexity, leading to a complete loss of availability. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:spa_501g_firmware:*:sr1:*:*:*:*:*:* | ||
<= 7.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:spa_502g_firmware:*:sr1:*:*:*:*:*:* | ||
<= 7.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:spa_504g_firmware:*:sr1:*:*:*:*:*:* | ||
<= 7.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:spa_508g_firmware:*:sr1:*:*:*:*:*:* | ||
<= 7.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:spa_509g_firmware:*:sr1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.