{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:40:36Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20070320-CVE-2007-1542","slug":"cisco-sa-20070320-cve-2007-1542","vendor":"Cisco","title":"Cisco IP Phone SIP INVITE Message Denial of Service Vulnerability","summary":"Cisco 7940 and 7960 IP phones with firmware version 7.4 contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability exists due to an error within the handling of malformed SIP INVITE messages.&nbsp; An attacker could exploit this vulnerability by sending a crafted INVITE message to the device to cause it to reboot, resulting in a temporary DoS condition. Proof-of-concept code is available. Cisco confirmed this vulnerability and released updates to correct it. To exploit this vulnerability, the attacker must have access to the network on which the device resides.&nbsp; Another attack vector would be a SIP gateway that could pass the malicious SIP INVITE message to an affected device.&nbsp; Typically IP phones reside on their own network, which could prevent an external attacker from exploiting this vulnerability.&nbsp; However, an attacker with physical access to an IP phone could potentially unplug the phone and access the phone network directly from the connection that the IP phone normally plugs into. Cisco&nbsp;has released firmware version 8.6 is not affected by this vulnerability","severity":"Medium","published_at":"2007-03-20T16:35:15Z","updated_at":"2007-03-20T16:35:15Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20070320-CVE-2007-1542","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20070320-CVE-2007-1542/csaf/Cisco-SA-20070320-CVE-2007-1542.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.09184},"cves":[{"id":"CVE-2007-1542","kev":false,"epss":{"score":0.09184,"percentile":0.94771,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco IP phone","slug":"cisco-ip-phone","vendor":"Cisco"},"cve":{"id":"CVE-2007-1542"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:05:15Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco IP phone","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.09184,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2007-03-20T16:35:15Z","updated_at":"2007-03-20T16:35:15Z","advisory_updated_at":"2007-03-20T16:35:15Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20070320-CVE-2007-1542","row_display_order":1}]}