Description
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, which makes it easier for remote attackers to guess the RUDP ID and spoof messages. NOTE: this can be leveraged for an eavesdropping attack by sending many Open Audio Stream messages.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2007-5610 | The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, which makes it easier for remote attackers to guess the RUDP ID and spoof messages. NOTE: this can be leveraged for an eavesdropping attack by sending many Open Audio Stream messages. |
References
History
No history.
Subscriptions
Nortel
Subscribe
Business Communications Manager
Subscribe
Centrex Ip Client Manager
Subscribe
Centrex Ip Element Manager
Subscribe
Communications Server
Subscribe
Ip Audio Conference Phone 2033
Subscribe
Ip Phone 1110
Subscribe
Ip Phone 1120e
Subscribe
Ip Phone 1140e
Subscribe
Ip Phone 1150e
Subscribe
Ip Phone 2001
Subscribe
Ip Phone 2002
Subscribe
Ip Phone 2004
Subscribe
Ip Phone 2007
Subscribe
Meridian Option 11c
Subscribe
Meridian Option 51c
Subscribe
Meridian Option 61c
Subscribe
Meridian Option 81c
Subscribe
Meridian Sl100
Subscribe
Mobile Voice Client 2050
Subscribe
Multimedia Communication Server 5100
Subscribe
Multimedia Communication Server 5200
Subscribe
Wlan Handset 2210
Subscribe
Wlan Handset 2211
Subscribe
Wlan Handset 2212
Subscribe
Wlan Handset 6120
Subscribe
Wlan Handset 6140
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T15:39:13.714Z
Reserved: 2007-10-23T00:00:00.000Z
Link: CVE-2007-5638
No data.
Status : Deferred
Published: 2007-10-23T17:46:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-5638
No data.
OpenCVE Enrichment
No data.
EUVD