HIGH · 9.4

CVE-2008-1249

snomControl.swf in the central phone server for the Snom 320 SIP Phone allows remote attackers to cause a denial of service (application crash and corruption of call logs) via a "'); (double quote, qu...

Vulnerability Description

snomControl.swf in the central phone server for the Snom 320 SIP Phone allows remote attackers to cause a denial of service (application crash and corruption of call logs) via a "'); (double quote, quote, close parenthesis, semicolon) sequence in the "Call a number" field.

CVSS Score

9.4

HIGH

AV:N/AC:L/Au:N/C:N/I:C/A:C
Confidentiality
NONE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Snom320 Sip PhoneAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-1249?

CVE-2008-1249 is a vulnerability with a CVSS score of 9.4 (HIGH). snomControl.swf in the central phone server for the Snom 320 SIP Phone allows remote attackers to cause a denial of service (application crash and corruption of call logs) via a "'); (double quote, qu...

How severe is CVE-2008-1249?

CVE-2008-1249 has been rated HIGH with a CVSS base score of 9.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1249?

Check the references section above for vendor advisories and patch information. Affected products include: Snom 320 Sip Phone.