4.3
CVSSv2

CVE-2009-5139

Published: 12/02/2020 Updated: 14/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote malicious users to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google gizmo5 -

Exploits

PhonerLite SIP soft phone version 214 is vulnerable to revealing SIP MD5 digest authenticated user credential hash via spoofed SIP INVITE message sent by a malicious 3rd party After responding back to an authentication challenge to the BYE message, PhonerLite leaks the hashed MD5 digest credentials ...