First published: Tue Aug 28 2007(Updated: )
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thomson ST 2030 SIP phone | =1-1.52.1_firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4553 is classified as a denial of service vulnerability that can cause the device to hang.
To mitigate CVE-2007-4553, apply any available firmware updates for the Thomson ST 2030 SIP phone or configure the device to reject malformed SIP messages.
CVE-2007-4553 specifically affects the Thomson ST 2030 SIP phone running software version 1.52.1.
Yes, CVE-2007-4553 can be exploited remotely by sending a specially crafted INVITE message to the device.
The exploitation of CVE-2007-4553 results in the Thomson ST 2030 SIP phone hanging or becoming unresponsive.