PT-2007-4710 · Snom · Snom320-Sip+2

Published

2007-06-27

·

Updated

2008-11-15

·

CVE-2007-3439

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Snom 320 SIP Phone version 3.25, snom320-SIP version 6.2.3, and snom320 jffs version 23.36
Description The issue allows remote attackers to read a list of missed calls, received calls, and dialed numbers via a direct request to the web server on port 1800.
Recommendations For Snom 320 SIP Phone version 3.25, snom320-SIP version 6.2.3, and snom320 jffs version 23.36, restrict access to the web server on port 1800 to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3439

Affected Products

Snom 320 Sip Phone
Snom320 Jffs
Snom320-Sip