Lucene search

K
cveMitreCVE-2007-5493
HistoryOct 18, 2007 - 12:17 a.m.

CVE-2007-5493

2007-10-1800:17:00
CWE-264
mitre
web.nvd.nist.gov
28
cve-2007-5493
sms handler
windows mobile
pocket pc phone
vulnerability
wap push
pdu
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.012

Percentile

85.0%

The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.

Affected configurations

Nvd
Node
microsoftwindows_mobileMatch2005
VendorProductVersionCPE
microsoftwindows_mobile2005cpe:2.3:o:microsoft:windows_mobile:2005:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.012

Percentile

85.0%