PT-2003-2068 · Mediatrix Telecom · Mediatrix Telecom Voip Access Devices/Gateways
Publicado
2003-12-31
·
Atualizado
2017-07-11
·
CVE-2003-1114
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mediatrix Telecom VoIP Access Devices and Gateways versions SIPv2.4 through SIPv4.3
Description
The issue affects the Session Initiation Protocol (SIP) implementation, allowing remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages. This has been demonstrated by the OUSPG PROTOS c07-sip test suite.
Recommendations
For versions SIPv2.4 through SIPv4.3, consider disabling the SIP INVITE message handling until a patch is available to prevent potential denial of service or arbitrary code execution. Restrict access to the SIP implementation to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mediatrix Telecom Voip Access Devices/Gateways