CVE-2007-5361: High severity Alcatel-Lucent OmniPCX vulnerability
The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5361?
CVE-2007-5361 has a medium severity rating due to its potential to cause a denial of service.
How do I fix CVE-2007-5361?
To mitigate CVE-2007-5361, upgrade to a version of Alcatel-Lucent OmniPCX Enterprise that is later than 7.1.
What impact does CVE-2007-5361 have on VoIP communications?
CVE-2007-5361 can disrupt VoIP communications by misdirecting packets to a cached IP address.
What versions of OmniPCX are affected by CVE-2007-5361?
CVE-2007-5361 affects Alcatel-Lucent OmniPCX Enterprise version 7.1 and earlier.
Is remote exploitation possible with CVE-2007-5361?
Yes, CVE-2007-5361 can be exploited remotely, allowing attackers to cause a denial of service.