CVE-2007-3319: High severity Avaya 4602SW IP Phone vulnerability
The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers to conduct man-in-the-middle attacks and hijack or intercept communications.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3319?
CVE-2007-3319 is considered a high-severity vulnerability due to its potential to enable man-in-the-middle attacks.
How do I fix CVE-2007-3319?
To fix CVE-2007-3319, upgrade the Avaya 4602SW IP Phone to a firmware version later than 2.2.2.
What is the impact of CVE-2007-3319 on communications?
CVE-2007-3319 can result in remote attackers hijacking or intercepting SIP communications.
Which devices are affected by CVE-2007-3319?
CVE-2007-3319 specifically affects the Avaya 4602SW IP Phone models with SIP firmware versions 2.2.2 and earlier.
What type of authentication is vulnerable in CVE-2007-3319?
CVE-2007-3319 reveals a flaw in MD5 digest authentication that does not utilize the cnonce parameter.