The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device crash) via SIP (1) INVITE, (2) CANCEL, or unspecified other messages with a WWW-Authenticate header containing a crafted Digest domain.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Budgetone_200 | Grandstream | 1.1.1.5 (including) | 1.1.1.5 (including) |
Budgetone_200 | Grandstream | 1.1.1.14 (including) | 1.1.1.14 (including) |