CVE-2007-3443
The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing…
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered.
- CVSS 2.0
- 2.3 LOWAV:A/AC:M/Au:S/C:N/I:N/A:P
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Affected
- research in motion limited/blackberry 7270
- Source
- cve@mitre.org
References
- http://osvdb.org/37647
- http://secunia.com/advisories/25824
- http://www.blackberry.com/btsc/articles/220/KB12705_f.SAL_Public.html
- http://www.kb.cert.org/vuls/id/324841US Government Resource
- http://www.securityfocus.com/bid/24545
- http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=213&
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35075
- http://osvdb.org/37647
- http://secunia.com/advisories/25824
- http://www.blackberry.com/btsc/articles/220/KB12705_f.SAL_Public.html
- http://www.kb.cert.org/vuls/id/324841US Government Resource
- http://www.securityfocus.com/bid/24545
- http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=213&
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35075
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.