VulnerabilityModified
CVE-2008-5871
Nortel Multimedia Communication Server (MSC) 5100 3.0.13 does not verify credentials during call placement, which allows remote attackers to spoof and redirect VoIP calls, possibly related to the snoop command.
MEDIUM 6.4EPSS 1.61%
Does this matter?
Lower severity and a low EPSS score (1.61%). Track it; it rarely justifies an emergency change on its own.
Description
Nortel Multimedia Communication Server (MSC) 5100 3.0.13 does not verify credentials during call placement, which allows remote attackers to spoof and redirect VoIP calls, possibly related to the snoop command.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- nortel/multimedia communication server 5100
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32203Vendor Advisory
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=775223
- http://voipshield.com/research-details.php?id=119
- http://www.securityfocus.com/bid/31640
- http://www.vupen.com/english/advisories/2008/2779
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45752
- http://secunia.com/advisories/32203Vendor Advisory
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=775223
- http://voipshield.com/research-details.php?id=119
- http://www.securityfocus.com/bid/31640
- http://www.vupen.com/english/advisories/2008/2779
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45752
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.