← Back

CVE-2007-5640

nvd nist
Published: Oct 23, 2007Modified: Apr 23, 2026

JSON object

Loading...
7.1
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:C
Exploitability: 8.6 / Impact: 6.9
Source: NVD

Description

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.

Affected (16)

9 products
Business Communications Manager
Centrex Ip Client Manager
Centrex Ip Element Manager
Meridian Option 11c
Meridian Option 51c
Meridian Option 61c
Meridian Option 81c
Meridian Sl100
Mobile Voice Client 2050
Configuration A
16 vulnerable · 20 platform
Vulnerable SoftwareAffected Versions
Nortel
Version 1000
Version 200
Version 400
Version 50
Version 50a
Version 50e
Version srg200
Version srg50
All versions
All versions
All versions
All versions
All versions
All versions
Version cs2100
All versions
Running on/withPlatform Versions
Nortel
Multimedia Communication Server 5100
All versions
Nortel
Multimedia Communication Server 5200
All versions
Nortel
Communications Server
Version 1000e
Nortel
Communications Server
Version 1000m
Nortel
Communications Server
Version 1000s
Nortel
Communications Server
Version 2100
Nortel
Ip Audio Conference Phone 2033
All versions
Nortel
Ip Phone 1110
All versions
Nortel
Ip Phone 1120e
All versions
Nortel
Ip Phone 1140e
All versions
Nortel
Ip Phone 1150e
All versions
Nortel
Ip Phone 2001
All versions
Nortel
Ip Phone 2002
All versions
Nortel
Ip Phone 2004
All versions
Nortel
Ip Phone 2007
All versions
Nortel
Wlan Handset 2210
All versions
Nortel
Wlan Handset 2211
All versions
Nortel
Wlan Handset 2212
All versions
Nortel
Wlan Handset 6120
All versions
Nortel
Wlan Handset 6140
All versions

References (16)

Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.