← Vulnerability feed

Vulnerability record · CVE-2007-5361 · published 20 November 2007

CVE-2007-5361: Alcatel-lucent omnipcx vulnerability

AAlcatel Lucent · Omnipcx

The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.

8.5 CVSS 2.0 High EPSS 2.4% · top 17.0%
8.5CVSS 2.0 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.

AV:N/AC:L/Au:N/C:P/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5361 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-1691Alcatel-lucent omnipcx vulnerabilityAlcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthori…EPSS 3.6%7.5CVE-2007-2512Alcatel-lucent omnipcx vulnerabilityAlcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access …EPSS 1.2%6.2CVE-2002-0293Alcatel-lucent omnipcx vulnerabilityFTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.EPSS 0.29%5.8CVE-2011-0344Alcatel-lucent omnipcx memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Com…EPSS 2.3%5.0CVE-2003-1108Alcatel-lucent omnipcx vulnerabilityThe Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and po…EPSS 5.0%4.6CVE-2002-0295Alcatel-lucent omnipcx vulnerabilityAlcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.EPSS 0.31%2.1CVE-2002-0294Alcatel-lucent omnipcx vulnerabilityAlcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2007-5361), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.