{"api_version":"1","generated_at":"2026-05-14T01:32:02+00:00","cve":"CVE-2007-6190","urls":{"html":"https://cve.report/CVE-2007-6190","api":"https://cve.report/api/cve/CVE-2007-6190.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6190","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6190"},"summary":{"title":"CVE-2007-6190","description":"The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-30 01:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/26668","name":"http://www.securityfocus.com/bid/26668","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Unified IP Phone RTP Audio Stream Eavesdropping Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1019006","name":"http://securitytracker.com/id?1019006","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Cisco Unified IP Phone Extension Mobility Feature Lets Remote Authenticated Users Eavesdrop","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/4036","name":"http://www.vupen.com/english/advisories/2007/4036","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.hack.lu/pres/hacklu07_Remote_wiretapping.pdf","name":"http://www.hack.lu/pres/hacklu07_Remote_wiretapping.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://osvdb.org/40874","name":"http://osvdb.org/40874","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/27829","name":"http://secunia.com/advisories/27829","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Unified IP Phone Extension Mobility Weakness - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html","name":"http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Unified IP Phone Remote Eavesdropping  [Products & Services] - Cisco Systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6190","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6190","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6190","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"unified_ip_phone","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:54:27.074Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"26668","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26668"},{"name":"20071128 Cisco Unified IP Phone Remote Eavesdropping","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html"},{"name":"1019006","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1019006"},{"name":"27829","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27829"},{"name":"40874","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/40874"},{"name":"ADV-2007-4036","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/4036"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.hack.lu/pres/hacklu07_Remote_wiretapping.pdf"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-11-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-12-06T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"26668","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26668"},{"name":"20071128 Cisco Unified IP Phone Remote Eavesdropping","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html"},{"name":"1019006","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1019006"},{"name":"27829","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27829"},{"name":"40874","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/40874"},{"name":"ADV-2007-4036","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/4036"},{"tags":["x_refsource_MISC"],"url":"http://www.hack.lu/pres/hacklu07_Remote_wiretapping.pdf"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6190","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"26668","refsource":"BID","url":"http://www.securityfocus.com/bid/26668"},{"name":"20071128 Cisco Unified IP Phone Remote Eavesdropping","refsource":"CISCO","url":"http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html"},{"name":"1019006","refsource":"SECTRACK","url":"http://securitytracker.com/id?1019006"},{"name":"27829","refsource":"SECUNIA","url":"http://secunia.com/advisories/27829"},{"name":"40874","refsource":"OSVDB","url":"http://osvdb.org/40874"},{"name":"ADV-2007-4036","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/4036"},{"name":"http://www.hack.lu/pres/hacklu07_Remote_wiretapping.pdf","refsource":"MISC","url":"http://www.hack.lu/pres/hacklu07_Remote_wiretapping.pdf"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6190","datePublished":"2007-11-30T01:00:00.000Z","dateReserved":"2007-11-29T00:00:00.000Z","dateUpdated":"2024-08-07T15:54:27.074Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-30 01:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:N/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:unified_ip_phone:*:*:*:*:*:*:*:*","matchCriteriaId":"8231E975-3AA7-4B02-97EE-33397AFE70EB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6190","Ordinal":"1","Title":"CVE-2007-6190","CVE":"CVE-2007-6190","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6190","Ordinal":"1","NoteData":"The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream.","Type":"Description","Title":"CVE-2007-6190"},{"CveYear":"2007","CveId":"6190","Ordinal":"2","NoteData":"2007-11-29","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6190","Ordinal":"3","NoteData":"2007-12-06","Type":"Other","Title":"Modified"}]}}}