vendor:
sipXphone
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: sipXphone
Affected Version From: 2.6.0.27
Affected Version To: 2.6.0.27
Patch Exists: NO
Related CWE: CVE-2006-3524
CPE: sipXphone
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/sip/sipxphone_cseq, https://www.infosecmatter.com/nessus-plugin-library/?id=22092, https://www.infosecmatter.com/nessus-plugin-library/?id=74795, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
SIPfoundry sipXphone 2.6.0.27 CSeq Buffer Overflow
This module exploits a buffer overflow in SIPfoundry's sipXphone 2.6.0.27. By sending an overly long CSeq value, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the affected application.
Mitigation:
No known mitigation or remediation for this vulnerability