CVE-2007-3347
Published Jun 22, 2007
Last updated a year ago
Overview
- Description
- The D-Link DPH-540/DPH-541 phone accepts SIP INVITE messages that are not from the Call Server's IP address, which allows remote attackers to engage in arbitrary SIP communication with the phone, as demonstrated by communication with forged caller ID.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:C/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:d-link:dph-540:1.00.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ECC44D2A-6934-4FA5-A19D-D5D417120534" }, { "criteria": "cpe:2.3:h:d-link:dph-540:1.00.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F23E3A6B-A8A5-46E0-A768-8F89F25EB8DA" }, { "criteria": "cpe:2.3:h:d-link:dph-541:1.00.03:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "995CA3A4-7C10-41FB-8014-1548D531595C" }, { "criteria": "cpe:2.3:h:d-link:dph-541:1.00.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35997ABE-A289-4465-BD52-B34EE7F7A7D8" } ], "operator": "OR" } ] } ]