Description: | Summary: On December 3, 2015, the OpenSSL Project released a security advisory detailing five vulnerabilities. Cisco IP Phone 8800 Series incorporate a version of the OpenSSL package affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Vulnerability Insight: Multiple OpenSSL vulnerabilities affecting Cisco IP Phone 8800 Series:
- CVE-2015-3193: A vulnerability in the Montgomery multiplication module of OpenSSL could allow an unauthenticated, remote attacker to cause the library to produce unexpected and possibly weak cryptographic output.
- CVE-2015-3194: A vulnerability in OpenSSL could allow an unauthenticated, remote attacker to cause a DoS condition.
- CVE-2015-3195: A vulnerability in OpenSSL could allow an unauthenticated, remote attacker to cause a DoS condition.
- CVE-2015-3196: A vulnerability in OpenSSL could allow an unauthenticated, remote attacker to cause a DoS condition.
- CVE-2015-1794: A vulnerability in the anonymous Diffie-Hellman cipher suite in OpenSSL could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
Solution: Update to release 11.5(1) or later.
CVSS Score: 5.0
CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
|