5
CVSSv2

CVE-2002-1935

Published: 31/12/2002 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Pingtel Xpressa 1.2.5 up to and including 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote malicious users to avoid registering with the SIP registrar.

Vulnerable Product Search on Vulmon Subscribe to Product

pingtel xpressa 2.0

pingtel xpressa 1.2.8

pingtel xpressa 1.2.7.4

pingtel xpressa 1.2.5

pingtel xpressa 2.0.1