7.1

CVE-2007-4459

Exploit

Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a remote tag, followed by a certain set of two related SIP OPTIONS messages.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoVoip Phone Cp-7940 Updatep0s3-08-6-00_firmware Version <= 8.70
CiscoVoip Phone Cp-7940 Version3.0 Updatep0s3-08-6-00_firmware
CiscoVoip Phone Cp-7940 Version3.1 Updatep0s3-08-6-00_firmware
CiscoVoip Phone Cp-7940 Version3.2 Updatep0s3-08-6-00_firmware
CiscoVoip Phone Cp-7940 Version8.6 Updatep0s3-08-6-00_firmware
CiscoVoip Phone Cp-7960 Updatep0s3-08-6-00_firmware Version <= 8.70
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 35.31% 0.969
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.