Vulnerability Description
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a flood of Mute and UnMute messages that have a spoofed source IP address for the Signaling Server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nortel | Ip Audio Conference Phone 2033 | All versions |
| Nortel | Ip Phone 1110 | All versions |
| Nortel | Ip Phone 1120E | All versions |
| Nortel | Ip Phone 1140E | All versions |
| Nortel | Ip Phone 1150E | All versions |
| Nortel | Ip Phone 2001 | All versions |
| Nortel | Ip Phone 2002 | All versions |
| Nortel | Ip Phone 2004 | All versions |
| Nortel | Wlan Handset 2210 | All versions |
| Nortel | Wlan Handset 2211 | All versions |
| Nortel | Wlan Handset 2212 | All versions |
| Nortel | Wlan Handset 6120 | All versions |
| Nortel | Wlan Handset 6140 | All versions |
| Nortel | Ip Softphone 2050 | All versions |
| Nortel | Mobile Voice Client 2050 | All versions |
References
- http://securityreason.com/securityalert/3273
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=654715Patch
- http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_flooding_denial_of_serviExploit
- http://www.securityfocus.com/archive/1/482480/100/0/threaded
- http://www.securityfocus.com/bid/26122Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37253
- http://securityreason.com/securityalert/3273
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=654715Patch
- http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_flooding_denial_of_serviExploit
- http://www.securityfocus.com/archive/1/482480/100/0/threaded
- http://www.securityfocus.com/bid/26122Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37253
FAQ
What is CVE-2007-5639?
CVE-2007-5639 is a vulnerability with a CVSS score of 7.1 (HIGH). The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a...
How severe is CVE-2007-5639?
CVE-2007-5639 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5639?
Check the references section above for vendor advisories and patch information. Affected products include: Nortel Ip Audio Conference Phone 2033, Nortel Ip Phone 1110, Nortel Ip Phone 1120E, Nortel Ip Phone 1140E, Nortel Ip Phone 1150E.