HIGH · 7.1

CVE-2007-5640

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remot...

Vulnerability Description

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
NortelMultimedia Communication Server 5100All versions
NortelMultimedia Communication Server 5200All versions
NortelCommunications Server1000e
NortelIp Audio Conference Phone 2033All versions
NortelIp Phone 1110All versions
NortelIp Phone 1120EAll versions
NortelIp Phone 1140EAll versions
NortelIp Phone 1150EAll versions
NortelIp Phone 2001All versions
NortelIp Phone 2002All versions
NortelIp Phone 2004All versions
NortelIp Phone 2007All versions
NortelWlan Handset 2210All versions
NortelWlan Handset 2211All versions
NortelWlan Handset 2212All versions
NortelWlan Handset 6120All versions
NortelWlan Handset 6140All versions
NortelBusiness Communications Manager50
NortelCentrex Ip Client ManagerAll versions
NortelCentrex Ip Element ManagerAll versions

References

FAQ

What is CVE-2007-5640?

CVE-2007-5640 is a vulnerability with a CVSS score of 7.1 (HIGH). The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remot...

How severe is CVE-2007-5640?

CVE-2007-5640 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-5640?

Check the references section above for vendor advisories and patch information. Affected products include: Nortel Multimedia Communication Server 5100, Nortel Multimedia Communication Server 5200, Nortel Communications Server, Nortel Ip Audio Conference Phone 2033, Nortel Ip Phone 1110.