CVE-2002-0671

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:pingtel:xpressa_firmware:1.2.5:*:*:*:*:*:*:*
cpe:2.3:o:pingtel:xpressa_firmware:1.2.7.4:*:*:*:*:*:*:*
cpe:2.3:h:pingtel:xpressa:-:*:*:*:*:*:*:*

History

03 Feb 2024, 02:32

Type Values Removed Values Added
CPE cpe:2.3:h:pingtel:xpressa:1.2.7.4:*:*:*:*:*:*:*
cpe:2.3:h:pingtel:xpressa:1.2.5:*:*:*:*:*:*:*
cpe:2.3:o:pingtel:xpressa_firmware:1.2.5:*:*:*:*:*:*:*
cpe:2.3:o:pingtel:xpressa_firmware:1.2.7.4:*:*:*:*:*:*:*
cpe:2.3:h:pingtel:xpressa:-:*:*:*:*:*:*:*
References () http://www.atstake.com/research/advisories/2002/a071202-1.txt - () http://www.atstake.com/research/advisories/2002/a071202-1.txt - Broken Link
References () http://www.iss.net/security_center/static/9566.php - () http://www.iss.net/security_center/static/9566.php - Broken Link
References () http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp - Vendor Advisory () http://www.pingtel.com/PingtelAtStakeAdvisoryResponse.jsp - Broken Link, Vendor Advisory
References () http://www.securityfocus.com/bid/5224 - () http://www.securityfocus.com/bid/5224 - Broken Link, Third Party Advisory, VDB Entry
CVSS v2 : 7.5
v3 : unknown
v2 : 7.5
v3 : 9.8
CWE NVD-CWE-Other CWE-494
First Time Pingtel xpressa Firmware

Information

Published : 2002-07-23 04:00

Updated : 2024-02-03 02:32


NVD link : CVE-2002-0671

Mitre link : CVE-2002-0671

CVE.ORG link : CVE-2002-0671


JSON object : View

Products Affected

pingtel

  • xpressa
  • xpressa_firmware
CWE
CWE-494

Download of Code Without Integrity Check