SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3443

The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing…

LOW 2.3EPSS 0.60%

Does this matter?

Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.

Description

The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered.

CVSS 2.0
2.3 LOWAV:A/AC:M/Au:S/C:N/I:N/A:P
EPSS
0.60% probability · 47th percentile
CISA KEV
Not listed
Affected
research in motion limited/blackberry 7270
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.