Toll Fraud Vulnerability in Cisco CallManager Products
CVE-2007-5468

Currently unrated

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 October 2007

What is CVE-2007-5468?

The Cisco CallManager is susceptible to an authentication forward attack due to a failure to properly verify the Digest authentication header URI against the Request URI in Session Initiation Protocol (SIP) messages. This flaw permits remote attackers to exploit intercepted Digest authentication credentials, enabling them to initiate calls to arbitrary numbers or masquerade as different caller identities. This vulnerability poses significant risks of toll fraud and further exploits involving caller ID spoofing.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.