« Volver al listado

CVE-2007-3351

Estado: ModificadaAlta (7.8)—

The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a direct crafted INVITE transaction, which causes the phone to transmit many RTP packets.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3351",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-22T18:30:00.000",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/24549",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=217&",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35078",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24549",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=217&",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35078",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a direct crafted INVITE transaction, which causes the phone to transmit many RTP packets."
    },
    {
      "lang": "es",
      "value": "El software de teléfono SJPhone SIP 1.60.303c, cuando se instala en Dell Axim X3 ejecutando Windows Mobile 2003, permite a atacantes remotos provocar una denegación de servicio (cuelgue de dispositivo y amplificación de tráfico) mediante una transacción INVITE manipulada, que provoca que el teléfono transmita muchos paquetes RTP."
    }
  ],
  "lastModified": "2026-06-16T22:41:49.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_mobile:2003:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0793F3D0-B1E8-474F-A2E5-5B4BBE7E9B05"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:axim_x3:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AF3BA8CB-4FED-4021-A7CE-5F9F6DC0B42E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sj_labs:sjphone:1.60.303c:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A007CC4-DA6B-4A9B-B959-AEBE7BECB935"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}