Man-in-the-Middle Vulnerability in Avaya 4602SW IP Phone
CVE-2007-3319

Currently unrated

Key Information:

Vendor
Avaya
Vendor
CVE Published:
21 June 2007

Summary

The Avaya 4602SW IP Phone (Model 4602D02A) with SIP firmware versions 2.2.2 and earlier is vulnerable to man-in-the-middle attacks due to the lack of use of the cnonce parameter in the Authorization header during MD5 digest authentication. This oversight enables remote attackers to intercept or hijack communications, putting users at risk. Proper mitigations should be applied to secure affected devices and protect against unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.