CVE-2007-4553
Thomson ST 2030 SIP Phone 1.52.1 - Denial of Service via Malformed Via Header
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-4553. PoCs published by Humberto J. Abdelnur, MADYNES.
AI-analyzed exploit summary This Perl script exploits a denial-of-service vulnerability in Thomson SpeedTouch 2030 by sending a malformed SIP INVITE message via UDP. The crafted packet causes the device to stop responding, affecting firmware version 1.52.1.
Description
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number.
Exploits (2)
This Perl script exploits a denial-of-service vulnerability in Thomson SpeedTouch 2030 by sending a malformed SIP INVITE message via UDP. The crafted packet causes the device to stop responding, affecting firmware version 1.52.1.
This exploit sends a malformed SIP INVITE request via UDP to trigger a DoS condition in Thomson 2030 firmware v1.52.1. The payload contains a malformed 'To' header with special characters that cause the device to crash.