Vulnerabilities
Vulnerable Software
Pingtel:  >> Xpressa  >> 2.0.1  Security Vulnerabilities
application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.
CVSS Score
5.0
EPSS Score
0.01
Published
2004-09-13
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the physical password, and other registration information.
CVSS Score
5.0
EPSS Score
0.006
Published
2002-12-31
Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar.
CVSS Score
5.0
EPSS Score
0.006
Published
2002-12-31


Contact Us

Shodan ® - All rights reserved