I believe this one http://www.securityfocus.com/archive/1/488782 has not been mentioned undeservedly. By the way, it seems like Nortel did not address that vulnerability at all. -- regards, Dima