« Volver al listado

CVE-2007-3439

Estado: ModificadaMedia (5)—

The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to read a list of missed calls, received calls, and dialed numbers via a direct request to the web server on port 1800.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-3439",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-27T00:30:00.000",
  "references": [
    {
      "url": "http://osvdb.org/37753",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/25840",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24532",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=275&",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37753",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25840",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24532",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=275&",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to read a list of missed calls, received calls, and dialed numbers via a direct request to the web server on port 1800."
    },
    {
      "lang": "es",
      "value": "The Snom 320 SIP Phone, ejecutando snom320 linux 3.25, snom320-SIP 6.2.3, y snom320 jffs23.36, permite a atacantes remotos leer una lista de llamadas perdidas, recibidas y números marcados mediante una petición directa al servidor web por el puerto 1800."
    }
  ],
  "lastModified": "2026-06-16T22:42:02.567",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:snom:snom_320_linux:3.25:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8BB62879-400E-4BC8-8585-6B80EF028D0F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:snom:320_sip_phone:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "756F9732-B2CC-4CB5-82A0-405A8FF0D67E"
            },
            {
              "criteria": "cpe:2.3:h:snom:320_sip_phone:jffs23.36:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8500177D-A0B9-4B0E-BA9E-15DAF5A0E0AD"
            },
            {
              "criteria": "cpe:2.3:h:snom:320_sip_phone:sip_6.2.3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D30879D4-FE65-4EA5-8258-F55FF98AEC9D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}