{"api_version":"1","generated_at":"2026-07-23T06:07:41+00:00","cve":"CVE-2007-5469","urls":{"html":"https://cve.report/CVE-2007-5469","api":"https://cve.report/api/cve/CVE-2007-5469.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5469","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5469"},"summary":{"title":"CVE-2007-5469","description":"OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka \"toll fraud and authentication forward attack\").  NOTE: Debian disputes this issue, stating that \"having the two URIs mismatch is allowed by the standard and happens in some setups for valid reasons.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-10-16 00:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/27204","name":"http://secunia.com/advisories/27204","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"OpenSER Authentication Header Hijacking Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37197","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37197","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066691.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066691.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] Mailing List Charter","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/26057","name":"http://www.securityfocus.com/bid/26057","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco CallManager and Openser SIP Remote Unauthorized Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066581.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066581.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] Mailing List Charter","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066694.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066694.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] Mailing List Charter","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446956","name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446956","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#446956 - CVE-2007-5469 toll fraud and authentication forward attack - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5469","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5469","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5469","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openser","cpe5":"openser","cpe6":"1.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:31:58.907Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27204","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27204"},{"name":"20071012 CallManager and OpeSer toll fraud and authentication forward attack","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066581.html"},{"name":"26057","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26057"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446956"},{"name":"20071015 CallManager and OpeSer toll fraud and authentication forward attack","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066694.html"},{"name":"callmanager-openser-sip-call-hijacking(37197)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37197"},{"name":"20071015 CallManager and OpeSer toll fraud and authentication forward attack","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066691.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka \"toll fraud and authentication forward attack\").  NOTE: Debian disputes this issue, stating that \"having the two URIs mismatch is allowed by the standard and happens in some setups for valid reasons."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27204","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27204"},{"name":"20071012 CallManager and OpeSer toll fraud and authentication forward attack","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066581.html"},{"name":"26057","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26057"},{"tags":["x_refsource_MISC"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446956"},{"name":"20071015 CallManager and OpeSer toll fraud and authentication forward attack","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066694.html"},{"name":"callmanager-openser-sip-call-hijacking(37197)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37197"},{"name":"20071015 CallManager and OpeSer toll fraud and authentication forward attack","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066691.html"}],"tags":["disputed"],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-5469","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"** DISPUTED **  OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka \"toll fraud and authentication forward attack\").  NOTE: Debian disputes this issue, stating that \"having the two URIs mismatch is allowed by the standard and happens in some setups for valid reasons.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27204","refsource":"SECUNIA","url":"http://secunia.com/advisories/27204"},{"name":"20071012 CallManager and OpeSer toll fraud and authentication forward attack","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066581.html"},{"name":"26057","refsource":"BID","url":"http://www.securityfocus.com/bid/26057"},{"name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446956","refsource":"MISC","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=446956"},{"name":"20071015 CallManager and OpeSer toll fraud and authentication forward attack","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066694.html"},{"name":"callmanager-openser-sip-call-hijacking(37197)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37197"},{"name":"20071015 CallManager and OpeSer toll fraud and authentication forward attack","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-October/066691.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-5469","datePublished":"2007-10-16T00:00:00.000Z","dateReserved":"2007-10-15T00:00:00.000Z","dateUpdated":"2024-08-07T15:31:58.907Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-16 00:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openser:openser:1.2.2:*:*:*:*:*:*:*","matchCriteriaId":"482320A0-F065-442E-BFB4-2DD51A6DE1B0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5469","Ordinal":"1","Title":"CVE-2007-5469","CVE":"CVE-2007-5469","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5469","Ordinal":"1","NoteData":"OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka \"toll fraud and authentication forward attack\").  NOTE: Debian disputes this issue, stating that \"having the two URIs mismatch is allowed by the standard and happens in some setups for valid reasons.","Type":"Description","Title":"CVE-2007-5469"},{"CveYear":"2007","CveId":"5469","Ordinal":"2","NoteData":"2007-10-15","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5469","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}