Nortel · Business Communications Manager · CVE-2007-5637
**Name of the Vulnerable Software and Affected Versions**
Nortel UNIStim IP Softphone 2050 (affected versions not specified)
Nortel IP Phone 1140E (affected versions not specified)
Other Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines (affected versions not specified)
**Description**
The issue allows remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." This can be made easier by leveraging issues related to a small ID number space.
**Recommendations**
For Nortel UNIStim IP Softphone 2050, consider disabling the Open Audio Stream message functionality until a fix is available.
For Nortel IP Phone 1140E, restrict access to the device to minimize the risk of exploitation.
For other affected Nortel products, avoid using features that may enable "surveillance mode" until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.