Cisco 7940/7960 Voice over IP (VoIP) phones do not...
Moderate severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Feb 18, 2024
Description
Published by the National Vulnerability Database
Jul 11, 2005
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Feb 18, 2024
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
References