CVE-2007-1590: High severity Grandstream BudgeTone 200 vulnerability
The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1590?
CVE-2007-1590 is considered a high severity vulnerability because it allows remote attackers to cause a denial of service by crashing affected devices.
How do I fix CVE-2007-1590?
To fix CVE-2007-1590, update the Grandstream BudgeTone 200 IP phone to the latest firmware version that addresses this vulnerability.
Which devices are affected by CVE-2007-1590?
The affected devices for CVE-2007-1590 include the Grandstream BudgeTone 200 IP phones running program versions 1.1.1.14 and 1.1.1.5.
What types of attacks are possible with CVE-2007-1590?
CVE-2007-1590 allows remote attackers to exploit the vulnerability using crafted SIP INVITE and CANCEL messages to crash the device.
Is CVE-2007-1590 a common vulnerability?
While CVE-2007-1590 is known, it is essential to assess how frequently it affects deployed systems in service environments.