HIGH · 7.8

CVE-2007-3351

The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a...

Vulnerability Description

The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a direct crafted INVITE transaction, which causes the phone to transmit many RTP packets.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftWindows Mobile2003
DellAxim X3All versions
Sj LabsSjphone1.60.303c

References

FAQ

What is CVE-2007-3351?

CVE-2007-3351 is a vulnerability with a CVSS score of 7.8 (HIGH). The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a...

How severe is CVE-2007-3351?

CVE-2007-3351 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3351?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows Mobile, Dell Axim X3, Sj Labs Sjphone.