Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) To and From SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xpressa | Pingtel | 1.2.5 (including) | 1.2.5 (including) |
Xpressa | Pingtel | 1.2.7.4 (including) | 1.2.7.4 (including) |
Xpressa | Pingtel | 1.2.8 (including) | 1.2.8 (including) |
Xpressa | Pingtel | 2.0 (including) | 2.0 (including) |
Xpressa | Pingtel | 2.0.1 (including) | 2.0.1 (including) |