← Vulnerability feed

Vulnerability record · CVE-2007-5640 · published 23 October 2007

CVE-2007-5640: Nortel business communications manager vulnerability

Nortel · Business Communications Manager

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.

7.1 CVSS 2.0 High EPSS 1.8% · top 22.1%
7.1CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Nortel UNIStim IP Softphone 2050, IP Phone 1140E, and additional Nortel products from the IP Phone, Business Communications Manager (BCM), Mobile Voice Client, and other product lines, allow remote attackers to block calls and force re-registration via a resume message to the Signaling Server that has a spoofed source IP address for the phone. NOTE: the attack is more disruptive if a new spoofed resume message is sent after each re-registration.

AV:N/AC:M/Au:N/C:N/I:N/A:C

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5640 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-5640), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.