First published: Sun Jul 10 2005(Updated: )
Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream BudgeTone | =100 | |
All of | ||
Grandstream Bt-100 Firmware | ||
Grandstream BT-100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2182 is considered a moderate severity vulnerability due to its ability to allow remote attackers to spoof messages.
To fix CVE-2005-2182, ensure that your Grandstream BudgeTone 100 phones are updated to a firmware version that addresses this vulnerability.
The potential impacts of CVE-2005-2182 include unauthorized message spoofing, which can lead to misleading notifications such as fake voicemail indications.
CVE-2005-2182 specifically affects the Grandstream BudgeTone 100 Voice over IP (VoIP) phones.
Yes, CVE-2005-2182 can be exploited remotely by attackers to send spoofed NOTIFY messages to the affected VoIP devices.