CVE-2007-5637
Nortel Networks - Multiple UNIStim VoIP Products Remote Eavesdrop Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, y otros productos Nortel desde el IP Phone, Business Communications Manager (BCM), y otras líneas de producto permite a atacantes remotos espiar sobre el entorno físico a través de un mensaje Open Audio Stream que habilita "modo vigilante". NOTA: este asunto está relacionado con un espacio de números pequeño ID que podría apalancar para hacer más fácil el ataque.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-10-18 First Exploit
- 2007-10-23 CVE Reserved
- 2007-10-23 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://osvdb.org/41769 | Vdb Entry | |
http://securityreason.com/securityalert/3272 | Third Party Advisory | |
http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_surveillance_mode_v1.0.txt | X_refsource_misc | |
http://www.securityfocus.com/archive/1/482478/100/0/threaded | Mailing List | |
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/42/022870-01.pdf | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37255 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/30679 | 2007-10-18 | |
http://www.securityfocus.com/bid/26120 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=654714 | 2018-10-15 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27234 | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |