CVE-2005-2182: High severity Grandstream BudgeTone vulnerability
Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2182?
CVE-2005-2182 is considered a moderate severity vulnerability due to its ability to allow remote attackers to spoof messages.
How do I fix CVE-2005-2182?
To fix CVE-2005-2182, ensure that your Grandstream BudgeTone 100 phones are updated to a firmware version that addresses this vulnerability.
What are the potential impacts of CVE-2005-2182?
The potential impacts of CVE-2005-2182 include unauthorized message spoofing, which can lead to misleading notifications such as fake voicemail indications.
Which products are affected by CVE-2005-2182?
CVE-2005-2182 specifically affects the Grandstream BudgeTone 100 Voice over IP (VoIP) phones.
Can CVE-2005-2182 be exploited remotely?
Yes, CVE-2005-2182 can be exploited remotely by attackers to send spoofed NOTIFY messages to the affected VoIP devices.