CVE-2007-5637
Nortel Business Communications Manager - Information Disclosure
Title source: ruleDescription
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Daniel Stirnimann · perldoshardware
https://www.exploit-db.com/exploits/30679
Scores
EPSS
0.1065
EPSS Percentile
93.3%
Details
CWE
CWE-200
Status
published
Products (16)
nortel/business_communications_manager
50
nortel/business_communications_manager
50a
nortel/business_communications_manager
50e
nortel/business_communications_manager
200
nortel/business_communications_manager
400
nortel/business_communications_manager
1000
nortel/business_communications_manager
srg50
nortel/business_communications_manager
srg200
nortel/centrex_ip_client_manager
nortel/centrex_ip_element_manager
... and 6 more
Published
Oct 23, 2007
Tracked Since
Feb 18, 2026