CVE-2006-5233: High severity polycom soundpoint ip 301 vulnerability
Published Oct 11, 2006
·Updated
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a long URL sent to the HTTP daemon and (2) unspecified manipulations as demonstrated by the Nessus httpfingerprintinghmap.nasl script.
Affected Software
1 affected component
Polycom SoundPoint IP 301=1.4.1.0040
Event History
Oct 11, 2006
CVE Published
01:07 AM
Data Sourced
via NVD·01:07 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5233?
CVE-2006-5233 is classified as a denial of service vulnerability.
2
How do I fix CVE-2006-5233?
To mitigate CVE-2006-5233, consider upgrading the firmware of Polycom SoundPoint IP 301 to a version that addresses this vulnerability.
3
What type of attack does CVE-2006-5233 allow?
CVE-2006-5233 allows remote attackers to cause a reboot of the Polycom SoundPoint IP 301 phone.
4
Which version of Polycom SoundPoint IP 301 is affected by CVE-2006-5233?
CVE-2006-5233 specifically affects the Polycom SoundPoint IP 301 version 1.4.1.0040.
5
How is CVE-2006-5233 exploited?
CVE-2006-5233 can be exploited by sending a long URL to the HTTP daemon of the device.