Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2024-45276

Disclosure Date: October 15, 2024 (last updated January 24, 2025)
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
0
Attacker Value
Unknown

CVE-2024-45275

Disclosure Date: October 15, 2024 (last updated October 18, 2024)
The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.
Attacker Value
Unknown

CVE-2024-45274

Disclosure Date: October 15, 2024 (last updated October 18, 2024)
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
Attacker Value
Unknown

CVE-2024-45273

Disclosure Date: October 15, 2024 (last updated October 18, 2024)
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
Attacker Value
Unknown

CVE-2024-45271

Disclosure Date: October 15, 2024 (last updated October 22, 2024)
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
Attacker Value
Unknown

CVE-2024-5672

Disclosure Date: July 03, 2024 (last updated February 14, 2025)
A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.
0
Attacker Value
Unknown

CVE-2007-5640

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.
0
Attacker Value
Unknown

CVE-2007-5638

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines, use only 65536 different values in the 32-bit ID number field of an RUDP datagram, which makes it easier for remote attackers to guess the RUDP ID and spoof messages. NOTE: this can be leveraged for an eavesdropping attack by sending many Open Audio Stream messages.
0
Attacker Value
Unknown

CVE-2007-5637

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), and other product lines allow remote attackers to eavesdrop on the physical environment via an Open Audio Stream message that enables "surveillance mode." NOTE: issues relating to a small ID number space can be leveraged to make this attack easier.
0