CVE-2008-4999
Estado: ModificadaAlta (7.8)—💥 Exploit
Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: this issue could not be reproduced by a third party, who tested it on 0604DAD. In addition, the original researcher was not able to reliably reproduce the issue.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.83%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Nortel UNIStim IP Phone - Remote Ping Denial of Service (26/2/2008)
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://securityreason.com/securityalert/4568
- http://www.securityfocus.com/archive/1/488782/100/100/threaded
- http://www.securityfocus.com/archive/1/488801/100/100/threaded
- http://www.securityfocus.com/archive/1/488803/100/100/threaded
- http://www.securityfocus.com/bid/28004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40993
- http://securityreason.com/securityalert/4568
- http://www.securityfocus.com/archive/1/488782/100/100/threaded
- http://www.securityfocus.com/archive/1/488801/100/100/threaded
- http://www.securityfocus.com/archive/1/488803/100/100/threaded
- http://www.securityfocus.com/bid/28004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40993
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4999",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-11-07T19:36:24.087",
"references": [
{
"url": "http://securityreason.com/securityalert/4568",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/488782/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/488801/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/488803/100/100/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28004",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40993",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/4568",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/488782/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/488801/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/488803/100/100/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/28004",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40993",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet (\"ping of death\"). NOTE: this issue could not be reproduced by a third party, who tested it on 0604DAD. In addition, the original researcher was not able to reliably reproduce the issue."
},
{
"lang": "es",
"value": "El teléfono IP Nortel Networks UNIStim 0604DAS , permite a atacantes remotos provocar una denegación de servicio (caída) a través de un paquete ping largo (\"Ping de la muerte\"). Nota: Esta característica no ha podido ser reproducida por terceras partes, que lo chequearon en un 0604DAD. Como añadido, el desarrollador inicial no ha sido capaz de reproducir esta incidencia de forma fideligna.\r\n"
}
],
"lastModified": "2026-06-16T22:58:55.160",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:nortel:unistim_ip_phone:0604das:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B83A5C60-DB69-46CD-AEFB-186985904EB2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}