vendor:
estara softphone
by:
kokanin
5.5
CVSS
MEDIUM
estara softphone exploit
CWE
Product Name: estara softphone
Affected Version From: 3.0.1.2
Affected Version To: 3.0.1.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
damn-hippie.pl
Remote 'estara softphone' exploit that targets executable version 3.0.1.2. The exploit utilizes encoded bindshell on tcp/5060. It takes advantage of the fact that many users forward both tcp and udp port 5060 to their machine for sip stuff without considering the difference between the two.
Mitigation:
Patch/update the estara softphone to a version that fixes the vulnerability.