First published: Tue Oct 23 2007(Updated: )
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a flood of Mute and UnMute messages that have a spoofed source IP address for the Signaling Server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nortel IP Audio Conference Phone 2033 | ||
Nortel IP Phone 1110 | ||
Nortel IP Phone 1120E | ||
Nortel IP Phone 1140E | ||
Nortel IP Phone 1150E | ||
Nortel IP Phone 2001 | ||
Nortel IP Phone 2002 | ||
Nortel IP Phone 2004 | ||
Nortel WLAN Handset 2210 | ||
Nortel WLAN Handset 2211 | ||
Nortel WLAN Handset 2212 | ||
Nortel WLAN Handset | ||
Nortel WLAN Handset 6140 | ||
Nortel IP Softphone 2050 | ||
Nortel Mobile Voice Client 2050 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5639 is classified as a denial of service vulnerability.
CVE-2007-5639 allows attackers to cause a denial of service by flooding Nortel devices with spoofed mute and unmute messages.
CVE-2007-5639 affects the Nortel IP Softphone 2050, the Mobile Voice Client 2050, and certain WLAN Handsets.
To mitigate CVE-2007-5639, implement firewall rules that filter out the flood of mute and unmute messages from untrusted sources.
There is no specific patch mentioned for CVE-2007-5639, but it is advisable to check with Nortel for any firmware updates or recommendations.