CVE-2002-0671

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:pingtel:xpressa_firmware:1.2.5:*:*:*:*:*:*:*
cpe:2.3:o:pingtel:xpressa_firmware:1.2.7.4:*:*:*:*:*:*:*
cpe:2.3:h:pingtel:xpressa:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2002-07-23 04:00

Updated : 2024-02-03 02:32


NVD link : CVE-2002-0671

Mitre link : CVE-2002-0671

CVE.ORG link : CVE-2002-0671


JSON object : View

Products Affected

pingtel

  • xpressa_firmware
  • xpressa
CWE
CWE-494

Download of Code Without Integrity Check