CVE-2007-5639: High severity Nortel Ip Audio Conference Phone 2033 vulnerability
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a flood of Mute and UnMute messages that have a spoofed source IP address for the Signaling Server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5639?
CVE-2007-5639 is classified as a denial of service vulnerability.
How does CVE-2007-5639 affect Nortel devices?
CVE-2007-5639 allows attackers to cause a denial of service by flooding Nortel devices with spoofed mute and unmute messages.
What Nortel products are affected by CVE-2007-5639?
CVE-2007-5639 affects the Nortel IP Softphone 2050, the Mobile Voice Client 2050, and certain WLAN Handsets.
How can I mitigate CVE-2007-5639?
To mitigate CVE-2007-5639, implement firewall rules that filter out the flood of mute and unmute messages from untrusted sources.
Is there a patch available for CVE-2007-5639?
There is no specific patch mentioned for CVE-2007-5639, but it is advisable to check with Nortel for any firmware updates or recommendations.