Description: A vulnerability has been reported in Cisco 7940 and 7960 IP Phones, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the IP Stack. This can be exploited to cause the IP Phone to reload by sending a SYN flood to an arbitrary port.
Solution: Update to firmware revision 7.1(1) or later, which have the capability to perform load control using TCP throttling. This prevents a device from reloading.
Provided and/or discovered by: The vendor credits Knud Erik Højgaard.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.