Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
http://www.securitytracker.com/alerts/2005/Jul/1014406.html | vdb entry third party advisory broken link |
http://marc.info/?l=bugtraq&m=112067698624686&w=2 | mailing list |
http://pentest.tele-consulting.com/advisories/05_07_06_voip-phones.txt | broken link vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/21260 | vdb entry third party advisory |