CVE-2007-3322: Medium severity Avaya 4602SW IP Phone vulnerability
The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote attackers to cause a denial of service (audio quality loss) via a flood of packets to the RTP port.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3322?
CVE-2007-3322 is considered to be a moderate severity vulnerability due to its potential to disrupt audio quality.
How do I fix CVE-2007-3322?
To mitigate CVE-2007-3322, upgrade the firmware of the Avaya 4602 SW IP Phone to version 2.2.3 or later.
What devices are affected by CVE-2007-3322?
CVE-2007-3322 affects the Avaya 4602 SW IP Phone models running SIP firmware version 2.2.2 and earlier.
What type of attack does CVE-2007-3322 enable?
CVE-2007-3322 enables a denial of service attack that can degrade audio quality through packet flooding.
Is there a workaround for CVE-2007-3322 if I can't upgrade?
If unable to upgrade, limiting access to the RTP port or implementing network filtering may serve as a temporary workaround for CVE-2007-3322.