Vulnerabilities > CVE-2007-4498 - Remote Denial of Service vulnerability in Grandstream SIP Phone Gxv3000

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
COMPLETE
network
grandstream
exploit available

Summary

The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, eavesdrop on the phone's local environment, and cause a denial of service (blocked call reception) via a certain SIP INVITE message followed by a certain "SIP/2.0 183 Session Progress" message.

Vulnerable Configurations

Part Description Count
Hardware
Grandstream
3

Exploit-Db

descriptionGrandstream GXV-3000 Phone Remote Denial of Service Vulnerability. CVE-2007-4498. Dos exploit for hardware platform
idEDB-ID:30517
last seen2016-02-03
modified2007-08-22
published2007-08-22
reporterMADYNES
sourcehttps://www.exploit-db.com/download/30517/
titleGrandstream GXV-3000 Phone Remote Denial of Service Vulnerability