PT-2003-2068 · Mediatrix Telecom · Mediatrix Telecom Voip Access Devices/Gateways

Publicado

2003-12-31

·

Atualizado

2017-07-11

·

CVE-2003-1114

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mediatrix Telecom VoIP Access Devices and Gateways versions SIPv2.4 through SIPv4.3
Description The issue affects the Session Initiation Protocol (SIP) implementation, allowing remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages. This has been demonstrated by the OUSPG PROTOS c07-sip test suite.
Recommendations For versions SIPv2.4 through SIPv4.3, consider disabling the SIP INVITE message handling until a patch is available to prevent potential denial of service or arbitrary code execution. Restrict access to the SIP implementation to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1114

Produtos afetados

Mediatrix Telecom Voip Access Devices/Gateways