CVE-2007-5639
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a flood of Mute and UnMute messages that have a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and other Nortel IP Phone, Mobile Voice Client, and WLAN Handsets products allow remote attackers to cause a denial of service (device hang) via a flood of Mute and UnMute messages that have a spoofed source IP address for the Signaling Server.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- nortel/ip softphone 2050 · nortel/mobile voice client 2050
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/3273
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=654715Patch
- http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_flooding_denial_of_service_v1.0.txtExploit
- http://www.securityfocus.com/archive/1/482480/100/0/threaded
- http://www.securityfocus.com/bid/26122Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37253
- http://securityreason.com/securityalert/3273
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=654715Patch
- http://www.csnc.ch/static/advisory/csnc/nortel_IP_phone_flooding_denial_of_service_v1.0.txtExploit
- http://www.securityfocus.com/archive/1/482480/100/0/threaded
- http://www.securityfocus.com/bid/26122Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37253
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.