Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6190

Опубликовано: 30 нояб. 2007
Источник: nvd
CVSS2: 3.5
EPSS Низкий

Описание

The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:h:cisco:unified_ip_phone:*:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00364
Низкий

3.5 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
почти 4 года назад

The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream.

EPSS

Процентиль: 58%
0.00364
Низкий

3.5 Low

CVSS2

Дефекты

CWE-200