7.1

CVE-2007-5640

Exploit

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone.  NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NortelBusiness Communications Manager Version50
NortelBusiness Communications Manager Version50a
NortelBusiness Communications Manager Version50e
NortelBusiness Communications Manager Version200
NortelBusiness Communications Manager Version400
NortelBusiness Communications Manager Version1000
NortelBusiness Communications Manager Versionsrg50
NortelBusiness Communications Manager Versionsrg200
NortelCentrex Ip Client Manager
NortelCentrex Ip Element Manager
NortelMeridian Option 11c
NortelMeridian Option 51c
NortelMeridian Option 61c
NortelMeridian Option 81c
NortelMeridian Sl100 Versioncs2100
NortelMobile Voice Client 2050
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.17% 0.767
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C