CVE-2007-5637
Title: Nortel Ip Phone 1150E Information Disclosure
Information Disclosure
Proof Of Concept
PoC Available for CVE-2007-5637
CWE Category
CWE-200
Published Date
Oct 23, 2007
Modified Date
Apr 09, 2025
Exploit Status
Available
Score
4.3
CVSS v2.0
Exploit Probability (EPSS)
10.65%
Vulnerability Summary
CVE-2007-5637: The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.
Impacted Vendors
Reference Links
http://osvdb.org/41769
http://secunia.com/advisories/27234
http://securityreason.com/securityalert/3272
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=654714
http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_surveillance_mode_v1.0.txt
http://www.securityfocus.com/archive/1/482478/100/0/threaded
http://www.securityfocus.com/bid/26120
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/42/022870-01.pdf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37255
http://osvdb.org/41769
http://secunia.com/advisories/27234
http://securityreason.com/securityalert/3272
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=654714
http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_surveillance_mode_v1.0.txt
http://www.securityfocus.com/archive/1/482478/100/0/threaded
http://www.securityfocus.com/bid/26120
http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/42/022870-01.pdf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37255
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
4.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:P/I:N/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2007-5637 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/30679
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:P/I:N/A:N
Affected Stack
No specific products linked.