The vulnerability is caused due to an unspecified error in the SIP stack and can be exploited to set the phone to an inconsistent state by sending an "INVITE" and a "183 Session Progress" message sequence. This allows an attacker to eavesdrop with the device and also disables it to hang up.
The vulnerability is reported in firmware version 1.0.1.7. Other versions may also be affected.
Solution: Reportedly fixed in version 1.0.1.12. Contact the vendor for more information.