PT-2003-2068 · Mediatrix Telecom · Mediatrix Telecom Voip Access Devices/Gateways

Published

2003-12-31

·

Updated

2017-07-11

·

CVE-2003-1114

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mediatrix Telecom VoIP Access Devices and Gateways versions SIPv2.4 through SIPv4.3
Description The issue affects the Session Initiation Protocol (SIP) implementation, allowing remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages. This has been demonstrated by the OUSPG PROTOS c07-sip test suite.
Recommendations For versions SIPv2.4 through SIPv4.3, consider disabling the SIP INVITE message handling until a patch is available to prevent potential denial of service or arbitrary code execution. Restrict access to the SIP implementation to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1114

Affected Products

Mediatrix Telecom Voip Access Devices/Gateways