5
CVSSv2

CVE-2004-1680

Published: 13/09/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

pingtel xpressa 1.2.5

pingtel xpressa 2.0

pingtel xpressa 2.0.1

pingtel xpressa 2.1.11.24

pingtel xpressa 1.2.7.4

pingtel xpressa 1.2.8