Snom-320 SIP Remote Unauthorized Access Vulnerability
BID:24532
Info
Snom-320 SIP Remote Unauthorized Access Vulnerability
| Bugtraq ID: | 24532 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3439 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | Jun 29 2007 03:38PM |
| Credit: | Sipera VIPER Lab is credited with the discovery of this vulnerability. |
| Vulnerable: |
snom technology Snom 320 SIP Phone 6.2.3 SIP snom technology Snom 320 SIP Phone 3.3.6 jffs2 snom technology Snom 320 SIP Phone 3.2.5 linux |
| Not Vulnerable: | |
Discussion
Snom-320 SIP Remote Unauthorized Access Vulnerability
The snom 320 SIP VoIP phone is prone to a remote unauthorized-access vulnerability that may lead to information disclosure.
A remote attacker can exploit this issue to gain access to potentially sensitive information.
The snom 320 SIP VoIP phone is prone to a remote unauthorized-access vulnerability that may lead to information disclosure.
A remote attacker can exploit this issue to gain access to potentially sensitive information.
Exploit / POC
Snom-320 SIP Remote Unauthorized Access Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Snom-320 SIP Remote Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Snom-320 SIP Remote Unauthorized Access Vulnerability
References:
References:
- Snom 320 SIP VoIP Phone Product Page (snom technologies)
- VIPER-2007-035 Information leak vulnerability in Snom-320 SIP Phone may allow ac (Sipera)