PT-2007-6647 · Nortel · Business Communications Manager+2

Daniel Stirnimann

·

Published

2007-10-23

·

Updated

2018-10-15

·

CVE-2007-5637

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nortel UNIStim IP Softphone 2050 (affected versions not specified) Nortel IP Phone 1140E (affected versions not specified) Other Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines (affected versions not specified)
Description The issue allows remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." This can be made easier by leveraging issues related to a small ID number space.
Recommendations For Nortel UNIStim IP Softphone 2050, consider disabling the Open Audio Stream message functionality until a fix is available. For Nortel IP Phone 1140E, restrict access to the device to minimize the risk of exploitation. For other affected Nortel products, avoid using features that may enable "surveillance mode" until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5637

Affected Products

Business Communications Manager
Ip Phone 1140E
Unistim Ip Softphone 2050