Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-6190
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-6190

Description:
The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL attribute of an ExecuteItem element that specifies a Real-Time Transport Protocol (RTP) audio stream.

CVE Status:
Candidate

References:

ST
  1019006

SAID
  Secunia Advisory: SA27829

OSVDB
  40874

MISC
  http://www.hack.lu/pres/hacklu07_Remote_wiretapping.pdf

CISCO
  http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html

BID
  26668


Return to the previous page.