CVE-2007-5640: High severity Nortel Multimedia Communication Server 5100 vulnerability
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5640?
CVE-2007-5640 is classified with a medium severity level, indicating a potential impact on availability.
How do I fix CVE-2007-5640?
To mitigate CVE-2007-5640, ensure that your Nortel products are updated to the latest firmware versions and configurations recommended by Nortel.
What products are affected by CVE-2007-5640?
CVE-2007-5640 affects Nortel UNIStim IP Softphone 2050, IP Phone 1140E, Business Communications Manager, and various other Nortel products.
Can CVE-2007-5640 be exploited remotely?
Yes, CVE-2007-5640 can be exploited by remote attackers to block calls and force re-registration.
What type of attack does CVE-2007-5640 enable?
CVE-2007-5640 enables attackers to disrupt VoIP service by blocking calls and manipulating session registrations from a distance.