10

CVE-2007-5791

The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flood of messages triggering a denial of service, and by phone calls with malicious content.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.71% 0.883
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://osvdb.org/38524
http://osvdb.org/38525
http://secunia.com/advisories/27380
Vendor Advisory
http://www.securityfocus.com/bid/26129
http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=357
http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=360
https://exchange.xforce.ibmcloud.com/vulnerabilities/37416
https://exchange.xforce.ibmcloud.com/vulnerabilities/37420