CVE-2002-0671

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/07/2002
Last modified:
20/11/2024

Description

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:pingtel:xpressa_firmware:1.2.5:*:*:*:*:*:*:*
cpe:2.3:o:pingtel:xpressa_firmware:1.2.7.4:*:*:*:*:*:*:*
cpe:2.3:h:pingtel:xpressa:-:*:*:*:*:*:*:*