D-Link DPH-540/DPH-541 Wi-Fi Phone Security Bypass Vulnerability
BID:24560
Info
D-Link DPH-540/DPH-541 Wi-Fi Phone Security Bypass Vulnerability
| Bugtraq ID: | 24560 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3347 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2007 12:00AM |
| Updated: | Jun 26 2007 11:38PM |
| Credit: | Sipera VIPER Lab is credited with the discovery of this vulnerability. |
| Vulnerable: |
D-Link DPH-540/DPH-541 0 |
| Not Vulnerable: | |
Discussion
D-Link DPH-540/DPH-541 Wi-Fi Phone Security Bypass Vulnerability
The D-Link DPH-540/DPH-541 Wi-Fi phone is prone to a security-bypass vulnerability because it accepts SIP requests from random source IP addresses.
An attacker can exploit this issue to bypass security restrictions. The attacker may then be able to transmit malicious messages to the device.
The D-Link DPH-540/DPH-541 Wi-Fi phone is prone to a security-bypass vulnerability because it accepts SIP requests from random source IP addresses.
An attacker can exploit this issue to bypass security restrictions. The attacker may then be able to transmit malicious messages to the device.
Exploit / POC
D-Link DPH-540/DPH-541 Wi-Fi Phone Security Bypass Vulnerability
An attacker can exploit this issue using readily available VoIP utilities.
An attacker can exploit this issue using readily available VoIP utilities.
Solution / Fix
D-Link DPH-540/DPH-541 Wi-Fi Phone Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
D-Link DPH-540/DPH-541 Wi-Fi Phone Security Bypass Vulnerability
References:
References: