Pingtel xpressa SIP-based voice-over-IP phone 1.2.5...
High severity
Unreviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Feb 11, 2024
Description
Published by the National Vulnerability Database
Jul 23, 2002
Published to the GitHub Advisory Database
Apr 30, 2022
Last updated
Feb 11, 2024
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing.
References