First published: Fri Nov 30 2007(Updated: )
The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified IP Phones |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6190 is rated as a high severity vulnerability due to its potential for remote eavesdropping.
To mitigate CVE-2007-6190, disable the Extension Mobility feature on the Cisco Unified IP Phone if it is not required.
CVE-2007-6190 affects users of the Cisco Unified IP Phones when the Extension Mobility feature is enabled.
CVE-2007-6190 allows unauthorized remote users to eavesdrop on the physical environment through exploited features.
If you suspect exploitation of CVE-2007-6190, immediately review security settings and disable the affected feature.