CVE-2007-2512: High severity Alcatel-Lucent OmniPCX vulnerability
Published Jun 7, 2007
·Updated
Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems.
Affected Software
2 affected components
Alcatel-Lucent OmniPCX
Alcatel-Lucent OmniPCX=7.0
Event History
Jun 7, 2007
CVE Published
09:30 PM
Data Sourced
09:30 PM
DescriptionWeaknessAffected Software
Jun 8, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2512?
CVE-2007-2512 is considered a high severity vulnerability due to its potential to allow unauthorized access to the voice VLAN.
2
How do I fix CVE-2007-2512?
To fix CVE-2007-2512, disable the mini switch feature on Alcatel-Lucent IP-Touch Telephones running OmniPCX Enterprise.
3
What are the potential risks associated with CVE-2007-2512?
The risks of CVE-2007-2512 include unauthorized access to sensitive voice data and disruption of voice services.
4
Which versions of Alpine are affected by CVE-2007-2512?
CVE-2007-2512 affects Alcatel-Lucent OmniPCX versions 7.0 and later.
5
Is there a workaround for CVE-2007-2512?
Yes, as a workaround, users can implement network segmentation to isolate affected devices.