Avaya 4602SW IP Phone Security Bypass Vulnerability
BID:24544
Info
Avaya 4602SW IP Phone Security Bypass Vulnerability
| Bugtraq ID: | 24544 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3320 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Sipera VIPER Lab is credited with the discovery of this vulnerability. |
| Vulnerable: |
Avaya 4602 SW IP Phone (Model 4602D02A) 0 |
| Not Vulnerable: | |
Discussion
Avaya 4602SW IP Phone Security Bypass Vulnerability
The Avaya 4602SW IP phone is prone to a security-bypass vulnerability because it accepts SIP requests from random source IP addresses.
An attacker can exploit this issue to bypass security restrictions and then transmit malicious messages to the device.
This issue affects the Avaya 4602SW IP Phone (Model 4602D02A).
The Avaya 4602SW IP phone is prone to a security-bypass vulnerability because it accepts SIP requests from random source IP addresses.
An attacker can exploit this issue to bypass security restrictions and then transmit malicious messages to the device.
This issue affects the Avaya 4602SW IP Phone (Model 4602D02A).
Exploit / POC
Avaya 4602SW IP Phone Security Bypass Vulnerability
An attacker can exploit this issue using readily available VoIP utilities.
An attacker can exploit this issue using readily available VoIP utilities.
Solution / Fix
Avaya 4602SW IP Phone Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Avaya 4602SW IP Phone Security Bypass Vulnerability
References:
References:
- Avaya 4602SW SIP Phone accepts SIP requests from random source IP address (Sipera VIPER Lab)
- Avaya Homepage (Avaya Inc.)