CVE-2007-5637

Nortel Business Communications Manager - Unauthenticated Eavesdropping via Open Audio Stream

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5637. PoCs published by Daniel Stirnimann.

AI-analyzed exploit summary This exploit sends spoofed UNIStim messages to a Nortel IP phone to force it into surveillance mode, allowing remote eavesdropping. It brute-forces the 16-bit message ID to bypass authentication.

Description

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Daniel Stirnimann · perldoshardware
https://www.exploit-db.com/exploits/30679

This exploit sends spoofed UNIStim messages to a Nortel IP phone to force it into surveillance mode, allowing remote eavesdropping. It brute-forces the 16-bit message ID to bypass authentication.

Classification
Working Poc 100%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Nortel IP Phone 1140E, IP Softphone 2050, and others
No auth needed
Prerequisites: Network access to the target IP phone · Knowledge of the signaling server IP address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37255
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41769
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27234
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3272
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/482478/100/0/threaded
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26120

Scores

EPSS 0.0313
EPSS Percentile 86.2%

Details

CWE
CWE-200
Status published
Products (16)
nortel/business_communications_manager 50
nortel/business_communications_manager 50a
nortel/business_communications_manager 50e
nortel/business_communications_manager 200
nortel/business_communications_manager 400
nortel/business_communications_manager 1000
nortel/business_communications_manager srg50
nortel/business_communications_manager srg200
nortel/centrex_ip_client_manager
nortel/centrex_ip_element_manager
... and 6 more
Published Oct 23, 2007
Tracked Since Feb 18, 2026