The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.

Project Subscriptions

Vendors Products
Business Communications Manager Subscribe
Centrex Ip Client Manager Subscribe
Centrex Ip Element Manager Subscribe
Communications Server Subscribe
Ip Audio Conference Phone 2033 Subscribe
Ip Phone 1110 Subscribe
Ip Phone 1120e Subscribe
Ip Phone 1140e Subscribe
Ip Phone 1150e Subscribe
Ip Phone 2001 Subscribe
Ip Phone 2002 Subscribe
Ip Phone 2004 Subscribe
Ip Phone 2007 Subscribe
Meridian Option 11c Subscribe
Meridian Option 51c Subscribe
Meridian Option 61c Subscribe
Meridian Option 81c Subscribe
Meridian Sl100 Subscribe
Mobile Voice Client 2050 Subscribe
Multimedia Communication Server 5100 Subscribe
Multimedia Communication Server 5200 Subscribe
Wlan Handset 2210 Subscribe
Wlan Handset 2211 Subscribe
Wlan Handset 2212 Subscribe
Wlan Handset 6120 Subscribe
Wlan Handset 6140 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2007-5612 The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T15:39:13.555Z

Reserved: 2007-10-23T00:00:00

Link: CVE-2007-5640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-10-23T17:46:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-5640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses