4.3
CVSSv2

CVE-2009-5140

Published: 12/02/2020 Updated: 14/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote malicious users to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linksys spa2102_firmware -

Exploits

PhonerLite SIP soft phone version 214 is vulnerable to revealing SIP MD5 digest authenticated user credential hash via spoofed SIP INVITE message sent by a malicious 3rd party After responding back to an authentication challenge to the BYE message, PhonerLite leaks the hashed MD5 digest credentials ...