vendor:
UNIStim IP Phone
by:
SecurityFocus
7.8
CVSS
HIGH
Remote Denial-of-Service
399
CWE
Product Name: UNIStim IP Phone
Affected Version From: 0604DAS
Affected Version To: Unknown
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Nortel UNIStim IP Phone Remote Denial-of-Service Vulnerability
Nortel UNIStim IP Phone products are prone to a remote denial-of-service vulnerability because the software fails to properly handle unexpected network datagrams. Successfully exploiting this issue allows remote attackers to crash affected phones, denying service to legitimate users. The following command will demonstrate this issue: ping -s 65500 <target>
Mitigation:
Ensure that all Nortel UNIStim IP Phone products are running the latest version of firmware.