MEDIUM · 4.3

CVE-2007-5637

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdr...

Vulnerability Description

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NortelMultimedia Communication Server 5100All versions
NortelMultimedia Communication Server 5200All versions
NortelCommunications Server1000e
NortelIp Audio Conference Phone 2033All versions
NortelIp Phone 1110All versions
NortelIp Phone 1120EAll versions
NortelIp Phone 1140EAll versions
NortelIp Phone 1150EAll versions
NortelIp Phone 2001All versions
NortelIp Phone 2002All versions
NortelIp Phone 2004All versions
NortelIp Phone 2007All versions
NortelWlan Handset 2210All versions
NortelWlan Handset 2211All versions
NortelWlan Handset 2212All versions
NortelWlan Handset 6120All versions
NortelWlan Handset 6140All versions
NortelBusiness Communications Manager50
NortelCentrex Ip Client ManagerAll versions
NortelCentrex Ip Element ManagerAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-5637?

CVE-2007-5637 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdr...

How severe is CVE-2007-5637?

CVE-2007-5637 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5637?

Check the references section above for vendor advisories and patch information. Affected products include: Nortel Multimedia Communication Server 5100, Nortel Multimedia Communication Server 5200, Nortel Communications Server, Nortel Ip Audio Conference Phone 2033, Nortel Ip Phone 1110.