SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-5493

The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.

MEDIUM 4.3EPSS 4.18%

Does this matter?

Lower severity and a low EPSS score (4.18%). Track it; it rarely justifies an emergency change on its own.

Description

The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
4.18% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
microsoft/windows mobile
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.