CVE Vulnerabilities

CVE-2007-5468

Published: Oct 16, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka toll fraud and authentication forward attack).

Affected Software

Name Vendor Start Version End Version
Call_manager Cisco 5.1.1.3000 (including) 5.1.1.3000 (including)

References