CVE Feed

    Dashboard / CVE / CVE-2007-5637

    CVE-2007-5637

    The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.

    Published:Oct 23, 2007
    Last Modified:Apr 23, 2026
    EPS:Oct 23, 2007
    EPSS Score:0.10654
    CVSS Score:4.3

    Affected Products

    Vendor
    Nortel
    Product
    Business Communications Manager
    Vendor
    Nortel
    Product
    Centrex Ip Client Manager
    Vendor
    Nortel
    Product
    Centrex Ip Element Manager
    Vendor
    Nortel
    Product
    Communications Server
    Vendor
    Nortel
    Product
    Ip Audio Conference Phone 2033
    Vendor
    Nortel
    Product
    Ip Phone 1110
    Vendor
    Nortel
    Product
    Ip Phone 1120e
    Vendor
    Nortel
    Product
    Ip Phone 1140e
    Vendor
    Nortel
    Product
    Ip Phone 1150e
    Vendor
    Nortel
    Product
    Ip Phone 2001
    Vendor
    Nortel
    Product
    Ip Phone 2002
    Vendor
    Nortel
    Product
    Ip Phone 2004
    Vendor
    Nortel
    Product
    Ip Phone 2007
    Vendor
    Nortel
    Product
    Meridian Option 11c
    Vendor
    Nortel
    Product
    Meridian Option 51c
    Vendor
    Nortel
    Product
    Meridian Option 61c
    Vendor
    Nortel
    Product
    Meridian Option 81c
    Vendor
    Nortel
    Product
    Meridian Sl100
    Vendor
    Nortel
    Product
    Mobile Voice Client 2050
    Vendor
    Nortel
    Product
    Multimedia Communication Server 5100
    Vendor
    Nortel
    Product
    Multimedia Communication Server 5200
    Vendor
    Nortel
    Product
    Wlan Handset 2210
    Vendor
    Nortel
    Product
    Wlan Handset 2211
    Vendor
    Nortel
    Product
    Wlan Handset 2212
    Vendor
    Nortel
    Product
    Wlan Handset 6120
    Vendor
    Nortel
    Product
    Wlan Handset 6140

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High