PT-2009-1348 · Nortel · Nortel Multimedia Communication Server 5100
Published
2009-01-08
·
Updated
2017-08-08
·
CVE-2008-5871
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Nortel Multimedia Communication Server (MSC) 5100 version 3.0.13
Description
The issue allows remote attackers to spoof and redirect VoIP calls due to a lack of credential verification during call placement. This might be related to the snoop command.
Recommendations
For version 3.0.13, consider restricting access to call placement functionality until a fix is available. As a temporary workaround, limiting the use of the snoop command might help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nortel Multimedia Communication Server 5100