PT-2007-6647 · Nortel · Business Communications Manager+2
Daniel Stirnimann
·
Publicado
2007-10-23
·
Atualizado
2018-10-15
·
CVE-2007-5637
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nortel UNIStim IP Softphone 2050 (affected versions not specified)
Nortel IP Phone 1140E (affected versions not specified)
Other Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines (affected versions not specified)
Description
The issue allows remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." This can be made easier by leveraging issues related to a small ID number space.
Recommendations
For Nortel UNIStim IP Softphone 2050, consider disabling the Open Audio Stream message functionality until a fix is available.
For Nortel IP Phone 1140E, restrict access to the device to minimize the risk of exploitation.
For other affected Nortel products, avoid using features that may enable "surveillance mode" until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Business Communications Manager
Ip Phone 1140E
Unistim Ip Softphone 2050