CVE-2008-4444: Input Validation
Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol (RTP) packet with malformed headers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4444?
CVE-2008-4444 has been classified as a medium-severity vulnerability that can lead to denial of service and potential remote code execution.
How do I fix CVE-2008-4444?
To fix CVE-2008-4444, update the firmware of Cisco Unified IP Phone 7960G and 7940G to at least version 8.10.
What devices are affected by CVE-2008-4444?
CVE-2008-4444 affects Cisco Unified IP Phone models 7940G and 7960G with specific firmware versions prior to 8.10.
Can CVE-2008-4444 be exploited remotely?
Yes, CVE-2008-4444 can be exploited by remote attackers via malformed Real-time Transport Protocol (RTP) packets.
What are the potential impacts of CVE-2008-4444?
The impacts of CVE-2008-4444 include device reboot and potentially arbitrary code execution on the affected devices.