ID

VAR-200706-0409


CVE

CVE-2007-3348


TITLE

D-Link DPH-540/DPH-541 Wi-Fi Phones SDP Header Denial Of Service Vulnerability

Trust: 0.9

sources: BID: 24538 // CNNVD: CNNVD-200706-361

DESCRIPTION

The D-Link DPH-540/DPH-541 phone allows remote attackers to cause a denial of service (device outage) via a malformed SDP header in a SIP INVITE message. D-Link DPH-540/DPH-541 Wi-Fi phone is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause certain features of the phone to become unusable until the phone has been reset. A denial of service vulnerability exists in the D-Link DPH-540/DPH-541 Wi-Fi Phones SDP Header

Trust: 1.98

sources: NVD: CVE-2007-3348 // JVNDB: JVNDB-2007-002226 // BID: 24538 // VULHUB: VHN-26710

AFFECTED PRODUCTS

vendor:d linkmodel:dph-540scope:eqversion:1.00.14

Trust: 1.6

vendor:d linkmodel:dph-541scope:eqversion:1.00.14

Trust: 1.6

vendor:d linkmodel:dph-541scope:eqversion:1.00.03

Trust: 1.6

vendor:d linkmodel:dph-540scope:eqversion:1.00.03

Trust: 1.6

vendor:d linkmodel:dph-540scope: - version: -

Trust: 0.8

vendor:d linkmodel:dph-541scope: - version: -

Trust: 0.8

vendor:d linkmodel:dph-540/dph-541scope:eqversion:0

Trust: 0.3

sources: BID: 24538 // JVNDB: JVNDB-2007-002226 // CNNVD: CNNVD-200706-361 // NVD: CVE-2007-3348

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-3348
value: HIGH

Trust: 1.0

NVD: CVE-2007-3348
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200706-361
value: HIGH

Trust: 0.6

VULHUB: VHN-26710
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-3348
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-26710
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-26710 // JVNDB: JVNDB-2007-002226 // CNNVD: CNNVD-200706-361 // NVD: CVE-2007-3348

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-3348

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200706-361

TYPE

Design Error

Trust: 0.9

sources: BID: 24538 // CNNVD: CNNVD-200706-361

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-002226

PATCH

title:Top Pageurl:http://www.dlink.com/

Trust: 0.8

sources: JVNDB: JVNDB-2007-002226

EXTERNAL IDS

db:NVDid:CVE-2007-3348

Trust: 2.8

db:BIDid:24538

Trust: 2.0

db:OSVDBid:36158

Trust: 1.7

db:SECUNIAid:25803

Trust: 1.7

db:VUPENid:ADV-2007-2320

Trust: 1.7

db:JVNDBid:JVNDB-2007-002226

Trust: 0.8

db:CNNVDid:CNNVD-200706-361

Trust: 0.7

db:VULHUBid:VHN-26710

Trust: 0.1

sources: VULHUB: VHN-26710 // BID: 24538 // JVNDB: JVNDB-2007-002226 // CNNVD: CNNVD-200706-361 // NVD: CVE-2007-3348

REFERENCES

url:http://www.securityfocus.com/bid/24538

Trust: 1.7

url:http://osvdb.org/36158

Trust: 1.7

url:http://secunia.com/advisories/25803

Trust: 1.7

url:http://www.vupen.com/english/advisories/2007/2320

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/35062

Trust: 1.1

url:http://www.sipera.com/index.php?action=resources%2cthreat_advisory&tid=218&

Trust: 1.0

url:http://www.sipera.com/index.php?action=resources,threat_advisory&tid=218&

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-3348

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-3348

Trust: 0.8

url:http://www.frsirt.com/english/advisories/2007/2320

Trust: 0.6

url:http://www.d-link.com/

Trust: 0.3

url:http://www.sipera.com/index.php?action=resources,threat_advisory&tid=218&

Trust: 0.1

sources: VULHUB: VHN-26710 // BID: 24538 // JVNDB: JVNDB-2007-002226 // CNNVD: CNNVD-200706-361 // NVD: CVE-2007-3348

CREDITS

Sipera VIPER Lab is credited with the discovery of this vulnerability.

Trust: 0.9

sources: BID: 24538 // CNNVD: CNNVD-200706-361

SOURCES

db:VULHUBid:VHN-26710
db:BIDid:24538
db:JVNDBid:JVNDB-2007-002226
db:CNNVDid:CNNVD-200706-361
db:NVDid:CVE-2007-3348

LAST UPDATE DATE

2025-04-10T23:07:27.319000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-26710date:2017-07-29T00:00:00
db:BIDid:24538date:2007-06-26T23:38:00
db:JVNDBid:JVNDB-2007-002226date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200706-361date:2007-06-25T00:00:00
db:NVDid:CVE-2007-3348date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-26710date:2007-06-22T00:00:00
db:BIDid:24538date:2007-03-26T00:00:00
db:JVNDBid:JVNDB-2007-002226date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200706-361date:2007-06-22T00:00:00
db:NVDid:CVE-2007-3348date:2007-06-22T18:30:00