7.1
CVE-2007-4459
- EPSS 35.31%
- Published 21.08.2007 21:17:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a remote tag, followed by a certain set of two related SIP OPTIONS messages.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Voip Phone Cp-7940 Updatep0s3-08-6-00_firmware Version <= 8.70
Cisco ≫ Voip Phone Cp-7940 Version3.0 Updatep0s3-08-6-00_firmware
Cisco ≫ Voip Phone Cp-7940 Version3.1 Updatep0s3-08-6-00_firmware
Cisco ≫ Voip Phone Cp-7940 Version3.2 Updatep0s3-08-6-00_firmware
Cisco ≫ Voip Phone Cp-7940 Version8.6 Updatep0s3-08-6-00_firmware
Cisco ≫ Voip Phone Cp-7960 Updatep0s3-08-6-00_firmware Version <= 8.70
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 35.31% | 0.969 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.