{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T11:17:38Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20150629-CVE-2015-4226","slug":"cisco-sa-20150629-cve-2015-4226","vendor":"Cisco","title":"Cisco Unified IP Phones 9900 Series Denial of Service Vulnerability","summary":"A vulnerability in the packet storing capabilities of Cisco 9900 Series IP Phones could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. &nbsp; The vulnerability is due to how the phone decoder handles certain real-time transport protocol (RTP) packets. An attacker could exploit this vulnerability by calling a registered phone, waiting for a user to answer, then send malformed RTP packets to the user’s phone. A successful exploit could cause the phone to become unresponsive, resulting in a DoS condition. Cisco has confirmed the vulnerability and released software updates. To exploit this vulnerability, an attacker must first call a targeted phone and then rely on a user to answer the phone prior to sending malformed RTP packets. The attacker can not exploit this vulnerability without this requirement. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.","severity":"Medium","published_at":"2015-06-29T18:05:35Z","updated_at":"2015-06-29T18:05:35Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150629-CVE-2015-4226","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20150629-CVE-2015-4226/csaf/Cisco-SA-20150629-CVE-2015-4226.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.02774},"cves":[{"id":"CVE-2015-4226","kev":false,"epss":{"score":0.02774,"percentile":0.84762,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco Unified IP Phones 9900 Series Firmware","slug":"cisco-unified-ip-phones-9900-series-firmware","vendor":"Cisco"},"cve":{"id":"CVE-2015-4226"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:17:48Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Unified IP Phones 9900 Series Firmware","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.02774,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2015-06-29T18:05:35Z","updated_at":"2015-06-29T18:05:35Z","advisory_updated_at":"2015-06-29T18:05:35Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150629-CVE-2015-4226","row_display_order":1}]}