Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-5637

EPSS 10.65% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-5637

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Nortel多个VoIP产品UNIStim消息远程窃听漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Nortel IP Phone、IP Softphone等都是Nortel所发布的IP电话设备。 Nortel IP Phone实现上存在漏洞,远程攻击者可能利用此漏洞实现远程现场窃听。 如果用户发送了正确的UNIStim消息的话,就可能将IP电话置于监控模式。UNIStim消息ID必须匹配发送信号的服务器与IP电话之间的ID,但协议仅对ID数使用了16位长度。如果恶意用户发送了65536个穷尽了所有可能ID数的欺骗UNIStim消息的话,就可以打开音频通道,使IP电话的话筒处于远程监听的状态。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-5637

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-5637

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-10-23 · 66 CVEs total

CVE-2003-1439SILC Server SSH2本地内存中密码泄露漏洞
CVE-2003-1458ttCMS / ttForum Profile.php SQL注入漏洞
CVE-2003-1457Auerswald COMsuite CTI应用程序弱默认密码漏洞
CVE-2003-1456Mike Bobbitt album.pl远程任意命令执行漏洞
CVE-2003-1445RARLAB FAR文件管理器缓冲区溢出漏洞
CVE-2003-1444Kaspersky Antivirus (KAV)漏洞
CVE-2003-1443Kaspersky Antivirus (KAV)病毒保护绕过漏洞
CVE-2003-1442HM220dp ADSL modem WEB管理接口不安全漏洞
CVE-2003-1441Posadis DNS请求问题区远程拒绝服务漏洞
CVE-2003-1440SpamProbe远程拒绝服务漏洞
CVE-2003-1446Rogue变量扩展缓冲区溢出漏洞
CVE-2003-1438BEA Systems WebLogic Server和Express会话共享漏洞
CVE-2003-1437BEA WebLogic密钥库清除文本密码存储漏洞
CVE-2003-1436Nukebrowser远程包含漏洞
CVE-2003-1435PHP-Nuke modules.php远程可获取加密后口令漏洞
CVE-2003-1434login_ldap模块未授权访问漏洞
CVE-2003-1433Epic Games Unreal Engine多用户拒绝服务攻击漏洞
CVE-2003-1432Epic Games Unreal Engine内存消耗拒绝服务攻击漏洞
CVE-2003-1431Epic Games Unreal Engine Client Unreal URL服务拒绝漏洞
CVE-2003-1430Epic Games Unreal Engine Unreal URL目录遍历漏洞

Showing top 20 of 66 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-5637

No comments yet


Leave a comment