First published: Fri Jun 22 2007(Updated: )
The D-Link DPH-540/DPH-541 phone accepts SIP INVITE messages that are not from the Call Server's IP address, which allows remote attackers to engage in arbitrary SIP communication with the phone, as demonstrated by communication with forged caller ID.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dph-541 | =1.00.03 | |
D-Link DPH-540 | =1.00.14 | |
D-Link DPH-540 | =1.00.03 | |
D-link Dph-541 | =1.00.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3347 is considered a high severity vulnerability due to its potential to facilitate unauthorized SIP communication.
To mitigate CVE-2007-3347, ensure that the phone's SIP configuration restricts communication to authorized IP addresses.
CVE-2007-3347 affects the D-Link DPH-540 and DPH-541 phone models with specific versions mentioned in the vulnerability details.
CVE-2007-3347 allows remote attackers to send SIP INVITE messages leading to arbitrary communication, potentially with forged caller IDs.
There is no specific patch mentioned for CVE-2007-3347, but configuration changes can help mitigate the risks.