PT-2007-6647 · Nortel · Business Communications Manager+2
Daniel Stirnimann
·
Published
2007-10-23
·
Updated
2018-10-15
·
CVE-2007-5637
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nortel UNIStim IP Softphone 2050 (affected versions not specified)
Nortel IP Phone 1140E (affected versions not specified)
Other Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines (affected versions not specified)
Description
The issue allows remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." This can be made easier by leveraging issues related to a small ID number space.
Recommendations
For Nortel UNIStim IP Softphone 2050, consider disabling the Open Audio Stream message functionality until a fix is available.
For Nortel IP Phone 1140E, restrict access to the device to minimize the risk of exploitation.
For other affected Nortel products, avoid using features that may enable "surveillance mode" until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Business Communications Manager
Ip Phone 1140E
Unistim Ip Softphone 2050