VulnerabilityModified
CVE-2007-3320
The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to have an unspecified impact.
MEDIUM 5.0EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to have an unspecified impact.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- avaya/4602sw ip phone
- Source
- cve@mitre.org
References
- http://osvdb.org/38116
- http://secunia.com/advisories/25747Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-263.htmVendor Advisory
- http://www.securityfocus.com/bid/24544
- http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=300&
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34971
- http://osvdb.org/38116
- http://secunia.com/advisories/25747Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-263.htmVendor Advisory
- http://www.securityfocus.com/bid/24544
- http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=300&
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34971
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.