CVE-2002-0670

The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.

Scoring

CVSS base score
0.05
EPSS probability
1.26%
Published
2002-07-15
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs