CVE-2007-5638: Infoleak
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, which makes it easier for remote attackers to guess the RUDP ID and spoof messages. NOTE: this can be leveraged for an eavesdropping attack by sending many Open Audio Stream messages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5638?
The severity of CVE-2007-5638 is considered moderate as it allows for potential remote attacks through exploitation of ID number field limitations.
How do I fix CVE-2007-5638?
To fix CVE-2007-5638, ensure that your Nortel products are updated to the latest firmware version that addresses this vulnerability.
What Nortel products are affected by CVE-2007-5638?
Affected products include Nortel IP Softphone 2050, IP Phone 1140E, and various models from the Nortel Business Communications Manager and Meridian series.
Can CVE-2007-5638 be exploited remotely?
Yes, CVE-2007-5638 can be exploited remotely due to its nature of allowing attackers to guess ID numbers in RUDP datagrams.
What are the potential impacts of CVE-2007-5638?
The potential impacts of CVE-2007-5638 include unauthorized access and the ability to disrupt communication services through successful attacks.