Back to Database
Status published
High
CVE-2008-6564
Nortel UNIStim protocol, as used in Communication Server 1000 and...
Vulnerability Description
Nortel UNIStim protocol, as used in Communication Server 1000 and other products, uses predictable sequence numbers, which allows remote attackers to hijack sessions via sniffing or brute force attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-6564
Credits & Attribution
No credits recorded in the NVD database.
References
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=713455
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41801
- http://osvdb.org/44379
- http://secunia.com/advisories/29747
- http://www.voipshield.com/research-details.php?id=27&s=4&threats_details=&threats_category=0&threats_vendor=0&limit=20&sort=discovered&sortby=DESC
- http://www.securityfocus.com/bid/28691
- http://www.securitytracker.com/id?1019847
More from nortel
View All →CVE-2008-6579
Nortel Communication Server 1000 4.50.x allows remote attackers to obtain...
Medium
5
CVE-2008-6578
Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow...
Critical
10
CVE-2008-6577
Nortel MG1000S, Signaling Server, and Call Server on the Communications...
Critical
10
CVE-2008-6576
Unspecified vulnerability in the "session limitation technique" in the FTP...
High
7.8
CVE-2008-5872
Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP)...
High
7.8
Affected Vendor
nortel
View all reports →Affected Software
communication server 1000, unistim protocol
Vulnerable Versions:
Unknown
Timeline
Official Publish:
March 31st, 2009
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.