PT-2007-6604 · Cisco · Cisco Ip Phone 7940
Humberto J. Abdelnur
+2
·
Published
2007-12-18
·
Updated
2017-09-29
·
CVE-2007-5583
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IP Phone 7940 with firmware P0S3-08-7-00
Description
The issue allows remote attackers to cause a denial of service, resulting in either "486 Busy" responses or device reboot. This is achieved through a sequence of SIP INVITE transactions where the Request-URI lacks a user name.
Recommendations
For Cisco IP Phone 7940 with firmware P0S3-08-7-00, consider restricting access to the SIP INVITE transaction to minimize the risk of exploitation until a fix is available.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ip Phone 7940