PT-2007-4711 · Snom · Snom320-Sip+2
Published
2007-06-27
·
Updated
2008-11-15
·
CVE-2007-3440
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Snom 320 SIP Phone version 3.25, snom320-SIP version 6.2.3, and snom320 jffs version 23.36
Description
The issue allows remote attackers to place calls to arbitrary phone numbers via certain requests to the "web server on port 1800".
Recommendations
For Snom 320 SIP Phone version 3.25, snom320-SIP version 6.2.3, and snom320 jffs version 23.36, restrict access to the web server on port 1800 to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snom 320 Sip Phone
Snom320 Jffs
Snom320-Sip