Lucene search

K

Phone Security Vulnerabilities

cve
cve

CVE-2008-0529

Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted...

7.5AI Score

0.079EPSS

2008-02-15 02:00 AM
21
cve
cve

CVE-2008-0527

The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP...

6.5AI Score

0.01EPSS

2008-02-15 02:00 AM
21
cve
cve

CVE-2007-5583

Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequence of SIP INVITE transactions in which the Request-URI lacks a user name, a different vulnerability than...

6.5AI Score

0.822EPSS

2007-12-18 01:46 AM
22
cve
cve

CVE-2007-6190

The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an...

6AI Score

0.003EPSS

2007-11-30 01:46 AM
19
cve
cve

CVE-2007-5791

The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flood of messages triggering a denial of service, and by phone calls with...

6.8AI Score

0.041EPSS

2007-11-01 04:46 PM
26
4
cve
cve

CVE-2007-5792

The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network and reconstructing the RTP...

6.7AI Score

0.003EPSS

2007-11-01 04:46 PM
20
cve
cve

CVE-2007-5638

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, which makes it easier for remote attackers to...

6.5AI Score

0.008EPSS

2007-10-23 05:46 PM
18
cve
cve

CVE-2007-5639

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a flood of Mute and UnMute messages that have a spoofed source IP address for the Signaling...

6.7AI Score

0.021EPSS

2007-10-23 05:46 PM
17
cve
cve

CVE-2007-5637

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode.".....

6.5AI Score

0.057EPSS

2007-10-23 05:46 PM
21
cve
cve

CVE-2007-5640

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server.....

6.7AI Score

0.021EPSS

2007-10-23 05:46 PM
19
cve
cve

CVE-2007-3286

Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unspecified...

7.9AI Score

0.027EPSS

2007-09-19 06:17 PM
25
cve
cve

CVE-2007-4753

The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via (1) an empty SIP message or (2) a SIP INVITE message with a malformed To header, different vectors than...

6.6AI Score

0.148EPSS

2007-09-08 12:17 AM
14
cve
cve

CVE-2007-4553

The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version...

6.5AI Score

0.148EPSS

2007-08-28 12:17 AM
23
cve
cve

CVE-2007-4498

The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, eavesdrop on the phone's local environment, and cause a denial of service (blocked call reception) via a certain SIP INVITE message followed by a...

6.6AI Score

0.776EPSS

2007-08-23 07:17 PM
19
cve
cve

CVE-2007-4459

Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a.....

6.7AI Score

0.822EPSS

2007-08-21 09:17 PM
28
cve
cve

CVE-2007-3440

The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to place calls to arbitrary phone numbers via certain requests to the web server on port...

6.8AI Score

0.013EPSS

2007-06-27 12:30 AM
20
cve
cve

CVE-2007-3441

Format string vulnerability in the Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to cause a denial of service (blocked call reception and slow calling) via format string specifiers in an SDP header value, a different vulnerability than...

6.6AI Score

0.021EPSS

2007-06-27 12:30 AM
25
cve
cve

CVE-2007-3439

The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to read a list of missed calls, received calls, and dialed numbers via a direct request to the web server on port...

6.6AI Score

0.006EPSS

2007-06-27 12:30 AM
28
cve
cve

CVE-2007-3445

Buffer overflow in SJ Labs SJphone 1.60.303c, running under Windows Mobile 2003 on the Samsung SCH-i730 phone, allows remote attackers to cause a denial of service (device hang and call termination) via a malformed SIP INVITE message, a different vulnerability than...

6.7AI Score

0.011EPSS

2007-06-27 12:30 AM
16
cve
cve

CVE-2007-3349

The Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to (1) cause a denial of service (device freeze) via a malformed SIP message of a certain length or (2) cause a denial of service (continuous ring) via a malformed SIP message of a certain other...

6.7AI Score

0.021EPSS

2007-06-22 06:30 PM
28
cve
cve

CVE-2007-3361

The Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to cause a denial of service (device crash) via a SIP message with a malformed...

6.5AI Score

0.021EPSS

2007-06-22 06:30 PM
17
cve
cve

CVE-2007-3319

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers to conduct man-in-the-middle attacks and hijack or intercept...

6.7AI Score

0.01EPSS

2007-06-21 06:30 PM
22
cve
cve

CVE-2007-3322

The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote attackers to cause a denial of service (audio quality loss) via a flood of packets to the RTP...

6.8AI Score

0.018EPSS

2007-06-21 06:30 PM
30
cve
cve

CVE-2007-3320

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to have an unspecified...

7AI Score

0.033EPSS

2007-06-21 06:30 PM
24
cve
cve

CVE-2007-3321

The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware allows remote attackers to cause a denial of service (device reboot) via a flood of packets to the BOOTP port...

6.7AI Score

0.018EPSS

2007-06-21 06:30 PM
32
cve
cve

CVE-2007-1072

The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows local users to obtain privileges or cause a denial of service via unspecified vectors. NOTE: this issue can be leveraged remotely via...

6.5AI Score

0.012EPSS

2007-02-22 10:28 PM
26
cve
cve

CVE-2007-1063

The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the...

6.5AI Score

0.012EPSS

2007-02-22 01:28 AM
33
cve
cve

CVE-2006-6411

PhoneCtrl.exe in Linksys WIP 330 Wireless-G IP Phone 1.00.06A allows remote attackers to cause a denial of service (crash) via a TCP SYN scan, as demonstrated using TCP ports 1-65535 with...

6.9AI Score

0.047EPSS

2006-12-10 02:28 AM
19
cve
cve

CVE-2006-5038

The FiWin SS28S WiFi VoIP SIP/Skype Phone, firmware version 01_02_07, has a hard-coded username and password, which allows remote attackers to gain administrative access via...

7.4AI Score

0.016EPSS

2006-09-27 11:07 PM
28
cve
cve

CVE-2005-4794

Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect...

7AI Score

0.125EPSS

2006-05-02 06:00 PM
28
cve
cve

CVE-2006-0360

MPM SIP HP-180W Wireless IP Phone WE.00.17 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require...

6.7AI Score

0.011EPSS

2006-01-22 08:03 PM
20
cve
cve

CVE-2006-0305

Clipcomm CPW-100E VoIP 802.11b Wireless Handset Phone running firmware 1.1.12 (051129) and CP-100E VoIP 802.11b Wireless Phone running firmware 1.1.60 allows remote attackers to gain unauthorized access via the debug service on TCP port...

7AI Score

0.028EPSS

2006-01-19 12:03 AM
20
cve
cve

CVE-2006-0302

ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port...

6.7AI Score

0.01EPSS

2006-01-19 12:03 AM
22
cve
cve

CVE-2006-0179

The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port...

6.9AI Score

0.036EPSS

2006-01-11 09:03 PM
25
cve
cve

CVE-2005-3803

Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive...

7.5CVSS

7.5AI Score

0.013EPSS

2005-11-24 11:03 AM
28
cve
cve

CVE-2005-3804

Cisco IP Phone (VoIP) 7920 1.0(8) listens to UDP port 17185 to support a VxWorks debugger, which allows remote attackers to obtain sensitive information and cause a denial of...

7.5AI Score

0.015EPSS

2005-11-24 11:03 AM
26
cve
cve

CVE-2005-3718

UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 does not allow users to disable access to (1) SNMP or (2) the rlogin port TCP 513, which allows remote attackers to exploit other vulnerabilities such as CVE-2005-3716, or execute arbitrary shell commands via rlogin,...

8AI Score

0.019EPSS

2005-11-21 11:03 AM
20
cve
cve

CVE-2005-3715

Senao SI-680H Wireless VoIP Phone Firmware 0.03.0839 leaves the VxWorks debugger UDP port 17185 available without authentication, which allows attackers to access the phone OS, obtain sensitive information, and cause a denial of...

7AI Score

0.005EPSS

2005-11-21 11:03 AM
23
cve
cve

CVE-2005-3720

The default index page in the HTTP server in Hitachi IP5000 VOIP WIFI Phone 1.5.6 lists sensitive information such as software...

6.6AI Score

0.003EPSS

2005-11-21 11:03 AM
27
cve
cve

CVE-2005-3721

The default configuration of the HTTP server in Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not require authentication for sensitive configuration pages, which allows remote attackers to modify...

7.2AI Score

0.007EPSS

2005-11-21 11:03 AM
23
cve
cve

CVE-2005-3724

Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require...

7.1AI Score

0.016EPSS

2005-11-21 11:03 AM
30
cve
cve

CVE-2005-3723

Hitachi IP5000 VOIP WIFI Phone 1.5.6 does not allow the user to disable access to (1) SNMP or (2) TCP port 3390, which allows remote attackers to modify configuration using CVE-2005-3722, or access the Unidata Shell to obtain sensitive information or cause a denial of...

7AI Score

0.012EPSS

2005-11-21 11:03 AM
21
cve
cve

CVE-2005-3717

The telnet daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has a default username "target" and password "password", which allows remote attackers to gain full access to the...

7.4AI Score

0.011EPSS

2005-11-21 11:03 AM
25
cve
cve

CVE-2005-3719

Hitachi IP5000 VOIP WIFI Phone 1.5.6 has a hard-coded administrator password of "0000", which allows attackers with physical access to obtain sensitive information and modify the phone's...

6.3AI Score

0.002EPSS

2005-11-21 11:03 AM
24
cve
cve

CVE-2005-3722

The SNMP v1/v2c daemon in Hitachi IP5000 VOIP WIFI Phone 1.5.6 allows remote attackers to gain read or write access to system configuration using arbitrary SNMP...

7.4AI Score

0.012EPSS

2005-11-21 11:03 AM
19
cve
cve

CVE-2005-3725

Zyxel P2000W Version 1 VOIP WIFI Phone Wj.00.10 uses hardcoded IP addresses for its DNS servers, which could allow remote attackers to cause a denial of service or hijack Zyxel phones by attacking or spoofing the hardcoded DNS servers. NOTE: it could be argued that this issue reflects an inherent.....

7AI Score

0.004EPSS

2005-11-21 11:03 AM
21
cve
cve

CVE-2005-2181

Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting"...

7.5CVSS

7AI Score

0.003EPSS

2005-07-11 04:00 AM
26
cve
cve

CVE-2005-1132

LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI...

6.9AI Score

0.013EPSS

2005-05-02 04:00 AM
23
cve
cve

CVE-2005-0506

The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as...

6.8AI Score

0.033EPSS

2005-03-14 05:00 AM
24
cve
cve

CVE-2003-1109

The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE...

7.7AI Score

0.044EPSS

2005-03-11 05:00 AM
22
Total number of security vulnerabilities255