Snom-320 SIP Phone Remote Phone Dialing Unauthorized Access Vulnerability
BID:24535
Info
Snom-320 SIP Phone Remote Phone Dialing Unauthorized Access Vulnerability
| Bugtraq ID: | 24535 |
| Class: | Design Error |
| CVE: |
CVE-2007-3440 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | Jun 29 2007 03:38PM |
| Credit: | Sipera VIPER Lab is credited with the discovery of this vulnerability. |
| Vulnerable: |
snom technology Snom 320 SIP Phone 6.2.3 SIP snom technology Snom 320 SIP Phone 3.3.6 jffs2 snom technology Snom 320 SIP Phone 3.2.5 linux |
| Not Vulnerable: | |
Discussion
Snom-320 SIP Phone Remote Phone Dialing Unauthorized Access Vulnerability
The snom 320 SIP VoIP phone is prone to a remote vulnerability that may allow an attacker to dial a random number.
The snom 320 SIP VoIP phone is prone to a remote vulnerability that may allow an attacker to dial a random number.
Exploit / POC
Snom-320 SIP Phone Remote Phone Dialing Unauthorized Access Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Snom-320 SIP Phone Remote Phone Dialing Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Snom-320 SIP Phone Remote Phone Dialing Unauthorized Access Vulnerability
References:
References:
- Snom 320 SIP VoIP Phone Product Page (snom technologies)
- VIPER-2007-036 Weak authentication vulnerability in Snom-320 SIP phone may allow (Sipera)