CVE-2007-5637: Infoleak
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5637?
CVE-2007-5637 is considered a high severity vulnerability due to its potential for enabling eavesdropping through an Open Audio Stream.
How do I fix CVE-2007-5637?
To address CVE-2007-5637, Nortel recommends applying the latest firmware updates and patches provided for the affected devices.
Which Nortel products are affected by CVE-2007-5637?
CVE-2007-5637 affects various Nortel products including IP Softphone 2050 and IP Phone 1140E among others.
What is the impact of CVE-2007-5637 on security?
The impact of CVE-2007-5637 allows attackers to remotely listen in on conversations, posing a significant security risk.
Is CVE-2007-5637 being actively exploited?
While there have been reported vulnerabilities, active exploitation of CVE-2007-5637 may vary, and organizations should remain vigilant.