First published: Fri Jan 16 2009(Updated: )
Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol (RTP) packet with malformed headers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified IP Phone 7940G | ||
Cisco Unified IP Phone 7960G Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4444 has been classified as a medium-severity vulnerability that can lead to denial of service and potential remote code execution.
To fix CVE-2008-4444, update the firmware of Cisco Unified IP Phone 7960G and 7940G to at least version 8.10.
CVE-2008-4444 affects Cisco Unified IP Phone models 7940G and 7960G with specific firmware versions prior to 8.10.
Yes, CVE-2008-4444 can be exploited by remote attackers via malformed Real-time Transport Protocol (RTP) packets.
The impacts of CVE-2008-4444 include device reboot and potentially arbitrary code execution on the affected devices.