Pingtel / Xpressa
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2002-1935 | Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) r… | MEDIUM | 5.0 | Jun 28, 2005 |
| CVE-2002-1934 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of… | MEDIUM | 5.0 | Jun 28, 2005 |
| CVE-2004-1680 | application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via… | MEDIUM | 5.0 | Feb 20, 2005 |
| CVE-2002-0674 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to per… | HIGH | 7.2 | Sep 1, 2004 |
| CVE-2002-0673 | The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out th… | MEDIUM | 4.6 | Sep 1, 2004 |
| CVE-2002-0672 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without auth… | MEDIUM | 4.6 | Sep 1, 2004 |
| CVE-2002-0668 | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and… | HIGH | 7.5 | Sep 1, 2004 |
| CVE-2002-0669 | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the S… | MEDIUM | 5.0 | Feb 11, 2003 |
| CVE-2002-0675 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unau… | MEDIUM | 4.6 | Jul 15, 2002 |
| CVE-2002-0670 | The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentica… | HIGH | 7.5 | Jul 15, 2002 |
| CVE-2002-0667 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain acces… | HIGH | 10.0 | Jul 15, 2002 |
Showing 1 to 11 of 11 CVEs