First published: Tue Nov 20 2007(Updated: )
The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alcatel-Lucent OmniPCX | <=7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5361 has a medium severity rating due to its potential to cause a denial of service.
To mitigate CVE-2007-5361, upgrade to a version of Alcatel-Lucent OmniPCX Enterprise that is later than 7.1.
CVE-2007-5361 can disrupt VoIP communications by misdirecting packets to a cached IP address.
CVE-2007-5361 affects Alcatel-Lucent OmniPCX Enterprise version 7.1 and earlier.
Yes, CVE-2007-5361 can be exploited remotely, allowing attackers to cause a denial of service.