7.8

CVE-2007-1590

The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrandstreamBudgetone 200 Version1.1.1.5
GrandstreamBudgetone 200 Version1.1.1.14
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.95% 0.891
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053099.html
Vendor Advisory
http://osvdb.org/34347
http://secunia.com/advisories/24538
Vendor Advisory
http://www.securityfocus.com/bid/23075
http://www.securitytracker.com/id?1017804
http://www.vupen.com/english/advisories/2007/1054
https://exchange.xforce.ibmcloud.com/vulnerabilities/33108