PT-2005-4470 · Senao+1 · Senao Si-680H Wireless Voip Phone+1
Published
2005-11-21
·
Updated
2011-03-08
·
CVE-2005-3715
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Senao SI-680H Wireless VoIP Phone Firmware version 0.03.0839
Description
The issue allows attackers to access the phone OS without authentication by exploiting the VxWorks debugger UDP port 17185. This can lead to obtaining sensitive information and causing a denial of service.
Recommendations
For Senao SI-680H Wireless VoIP Phone Firmware version 0.03.0839, consider disabling access to the VxWorks debugger UDP port 17185 until a patch is available. Restrict access to the phone OS to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Senao Si-680H Wireless Voip Phone
Vxworks