Vulnerability Description
The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1000S, Meridian-Core-Option 11C Chassis and Cabinet, and Meridian-Core-Option 51C, 61C, and 81C allows remote attackers to cause a denial of service (telephony application outage) via a flood of packets to Embedded LAN (ELAN) ports.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nortel | Communications Server | 1000e |
| Nortel | Meridian Option 11C | All versions |
| Nortel | Meridian Option 51C | All versions |
| Nortel | Meridian Option 61C | All versions |
| Nortel | Meridian Option 81C | All versions |
| Nortel | Voip-Core-Cs | 1000e |
References
- http://osvdb.org/41799
- http://secunia.com/advisories/27282Vendor Advisory
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=655204
- http://www.csnc.ch/static/advisory/csnc/nortel_telephony_server_denial_of_servic
- http://www.securityfocus.com/archive/1/482484/100/0/threaded
- http://www.securityfocus.com/bid/26113
- http://www.vupen.com/english/advisories/2007/3536Vendor Advisory
- http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/42/022871-01.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37252
- http://osvdb.org/41799
- http://secunia.com/advisories/27282Vendor Advisory
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=655204
- http://www.csnc.ch/static/advisory/csnc/nortel_telephony_server_denial_of_servic
- http://www.securityfocus.com/archive/1/482484/100/0/threaded
- http://www.securityfocus.com/bid/26113
FAQ
What is CVE-2007-5591?
CVE-2007-5591 is a vulnerability with a CVSS score of 7.8 (HIGH). The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1000S, Meridian-Core-Option 11C Chassis and Cabinet, and Meridian-Core-Option 51C...
How severe is CVE-2007-5591?
CVE-2007-5591 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5591?
Check the references section above for vendor advisories and patch information. Affected products include: Nortel Communications Server, Nortel Meridian Option 11C, Nortel Meridian Option 51C, Nortel Meridian Option 61C, Nortel Meridian Option 81C.