peter bassill · operator
$ cve CVE-2007-5637 JSON

CVE-2007-5637 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS3.13% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2007-10-23
Last modified2026-06-16

Affected (26)

VendorProduct
nortelbusiness communications manager
nortelcentrex ip client manager
nortelcentrex ip element manager
nortelcommunications server
nortelip audio conference phone 2033
nortelip phone 1110
nortelip phone 1120e
nortelip phone 1140e
nortelip phone 1150e
nortelip phone 2001
nortelip phone 2002
nortelip phone 2004
nortelip phone 2007
nortelmeridian option 11c
nortelmeridian option 51c
nortelmeridian option 61c
nortelmeridian option 81c
nortelmeridian sl100
nortelmobile voice client 2050
nortelmultimedia communication server 5100
nortelmultimedia communication server 5200
nortelwlan handset 2210
nortelwlan handset 2211
nortelwlan handset 2212
nortelwlan handset 6120
nortelwlan handset 6140

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD