« Volver al listado

CVE-2007-5591

Estado: ModificadaAlta (7.8)—

The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1000S, Meridian-Core-Option 11C Chassis and Cabinet, and Meridian-Core-Option 51C, 61C, and 81C allows remote attackers to cause a denial of service (telephony application outage) via a flood of packets to Embedded LAN (ELAN) ports.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-5591",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-10-19T23:17:00.000",
  "references": [
    {
      "url": "http://osvdb.org/41799",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/27282",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=655204",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.csnc.ch/static/advisory/csnc/nortel_telephony_server_denial_of_service_v1.0.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/482484/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/26113",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/3536",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/42/022871-01.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37252",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41799",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/27282",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=655204",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.csnc.ch/static/advisory/csnc/nortel_telephony_server_denial_of_service_v1.0.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/482484/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/26113",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/3536",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2007/42/022871-01.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37252",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1000S, Meridian-Core-Option 11C Chassis and Cabinet, and Meridian-Core-Option 51C, 61C, and 81C allows remote attackers to cause a denial of service (telephony application outage) via a flood of packets to Embedded LAN (ELAN) ports."
    },
    {
      "lang": "es",
      "value": "El servidor de señalización CS1000 en Nortel Enterprise VoIP-Core-CS 1000M Chasis/Cabinet, Enterprise VoIP-Core-CS 1000E y 1000S, Meridian-Core-Option 11C Chassis and Cabinet, y Meridian-Core-Option 51C, 61C y 81C, permite a atacantes remotos causar una denegación de servicio (interrupción de la aplicación de telefonía) por medio de una inundación de paquetes hacia puertos Embedded LAN (ELAN)."
    }
  ],
  "lastModified": "2026-06-16T22:46:27.427",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nortel:communications_server:1000e:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0EDBAFA1-329A-4321-990F-9B0972D286E8"
            },
            {
              "criteria": "cpe:2.3:a:nortel:communications_server:1000m:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9559937B-8F87-49AB-B572-2DB3477CB1BB"
            },
            {
              "criteria": "cpe:2.3:a:nortel:communications_server:1000s:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FA45C92F-3CDF-41A3-BD3F-E9725338E61F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nortel:meridian_option_11c:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C791034-CF75-4779-AB1B-DF7A67361A85"
            },
            {
              "criteria": "cpe:2.3:a:nortel:meridian_option_51c:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5D5C794-DF6D-492F-B34B-CDBB364C7168"
            },
            {
              "criteria": "cpe:2.3:a:nortel:meridian_option_61c:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9CBF345-9D72-459A-ADA2-33DE3A25D156"
            },
            {
              "criteria": "cpe:2.3:a:nortel:meridian_option_81c:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B726AC5D-3270-40D8-9783-F068A682A82D"
            },
            {
              "criteria": "cpe:2.3:a:nortel:voip-core-cs:1000e:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A739F443-E975-4D31-8207-941FA775F2CF"
            },
            {
              "criteria": "cpe:2.3:a:nortel:voip-core-cs:1000m:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4173D37F-FEB0-4F4D-8687-6869767A90C2"
            },
            {
              "criteria": "cpe:2.3:a:nortel:voip-core-cs:1000s:*:enterprise:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B4D3BC0-31E3-4A02-ACBC-BEB392BC2A1C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}