First published: Thu Jun 07 2007(Updated: )
Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alcatel-Lucent OmniPCX | ||
Alcatel-Lucent OmniPCX | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2512 is considered a high severity vulnerability due to its potential to allow unauthorized access to the voice VLAN.
To fix CVE-2007-2512, disable the mini switch feature on Alcatel-Lucent IP-Touch Telephones running OmniPCX Enterprise.
The risks of CVE-2007-2512 include unauthorized access to sensitive voice data and disruption of voice services.
CVE-2007-2512 affects Alcatel-Lucent OmniPCX versions 7.0 and later.
Yes, as a workaround, users can implement network segmentation to isolate affected devices.