// For flags

CVE-2007-4459

Cisco IP Phone 7940 - 10 SIP Messages Remote Denial of Service

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a remote tag, followed by a certain set of two related SIP OPTIONS messages.

Cisco IP Phone 7940 y 7960 con versión de firmware P0S3-08-6-00, y otro SIP versiones de firmware anteriores a 8.7(0), permite a atacantes remotos causar una denegación de servicio (reinicio del dispositivo) por medio de (1) una cierta secuencia de 10 mensajes SIP INVITE y OPTIONS no válidos; o (2) un determinado mensaje SIP INVITE no válido que contiene una etiqueta remota, seguido por un cierto ajuste de dos mensajes SIP OPTIONS relacionados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-08-21 CVE Reserved
  • 2007-08-21 CVE Published
  • 2007-08-21 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Voip Phone Cp-7940
Search vendor "Cisco" for product "Voip Phone Cp-7940"
<= 8.70
Search vendor "Cisco" for product "Voip Phone Cp-7940" and version " <= 8.70"
p0s3-08-6-00_firmware
Affected
Cisco
Search vendor "Cisco"
Voip Phone Cp-7940
Search vendor "Cisco" for product "Voip Phone Cp-7940"
3.0
Search vendor "Cisco" for product "Voip Phone Cp-7940" and version "3.0"
p0s3-08-6-00_firmware
Affected
Cisco
Search vendor "Cisco"
Voip Phone Cp-7940
Search vendor "Cisco" for product "Voip Phone Cp-7940"
3.1
Search vendor "Cisco" for product "Voip Phone Cp-7940" and version "3.1"
p0s3-08-6-00_firmware
Affected
Cisco
Search vendor "Cisco"
Voip Phone Cp-7940
Search vendor "Cisco" for product "Voip Phone Cp-7940"
3.2
Search vendor "Cisco" for product "Voip Phone Cp-7940" and version "3.2"
p0s3-08-6-00_firmware
Affected
Cisco
Search vendor "Cisco"
Voip Phone Cp-7940
Search vendor "Cisco" for product "Voip Phone Cp-7940"
8.6
Search vendor "Cisco" for product "Voip Phone Cp-7940" and version "8.6"
p0s3-08-6-00_firmware
Affected
Cisco
Search vendor "Cisco"
Voip Phone Cp-7960
Search vendor "Cisco" for product "Voip Phone Cp-7960"
<= 8.70
Search vendor "Cisco" for product "Voip Phone Cp-7960" and version " <= 8.70"
p0s3-08-6-00_firmware
Affected