← Back

CVE-2007-5468

nvd nist
Published: Oct 16, 2007Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka "toll fraud and authentication forward attack").

Affected (1)

Products: Cisco: Call Manager
1 product
Call Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.1.1.3000

Related CWEs

Timeline

No history available yet.