Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5468

Опубликовано: 16 окт. 2007
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka "toll fraud and authentication forward attack").

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:h:cisco:call_manager:5.1.1.3000:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00736
Низкий

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka "toll fraud and authentication forward attack").

EPSS

Процентиль: 72%
0.00736
Низкий

5 Medium

CVSS2

Дефекты

CWE-264