Vulnerabilities > CVE-2007-1590 - Remote Denial of Service vulnerability in Grandstream Budgetone 200 1.1.1.14/1.1.1.5

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
grandstream
exploit available

Summary

The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.

Vulnerable Configurations

Part Description Count
Hardware
Grandstream
2

Exploit-Db

descriptionGrandstream Budge Tone-200 IP Phone (Digest domain) DoS Exploit. CVE-2007-1590. Dos exploit for hardware platform
idEDB-ID:3535
last seen2016-01-31
modified2007-03-21
published2007-03-21
reporterMADYNES
sourcehttps://www.exploit-db.com/download/3535/
titleGrandstream Budge Tone-200 IP Phone Digest domain DoS Exploit