CVE-2007-2270
Linksys SPA941 - Denial of Service via SIP INVITE From Header
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-2270. PoCs published by MADYNES.
AI-analyzed exploit summary This exploit targets CVE-2007-2270, a SIP INVITE message handling vulnerability in certain VoIP software. It sends a malformed SIP INVITE message to trigger a denial-of-service condition by flooding the target with UDP packets.
Description
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.
Exploits (2)
This exploit targets CVE-2007-2270, a SIP INVITE message handling vulnerability in certain VoIP software. It sends a malformed SIP INVITE message to trigger a denial-of-service condition by flooding the target with UDP packets.
This exploit sends a malformed SIP INVITE request via UDP to trigger a denial-of-service (DoS) condition in vulnerable Linksys devices. The payload contains invalid characters (0xFF) to exploit a parsing vulnerability in the SIP stack.