A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
History

Wed, 14 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Mitel
Mitel 6863i Sip Firmware
Mitel 6865i Sip Firmware
Mitel 6867i Sip Firmware
Mitel 6869i Sip Firmware
Mitel 6873i Sip Firmware
Mitel 6905 Sip Firmware
Mitel 6910 Sip Firmware
Mitel 6915 Sip Firmware
Mitel 6920 Sip Firmware
Mitel 6920w Sip Firmware
Mitel 6930 Sip Firmware
Mitel 6930w Sip Firmware
Mitel 6940 Sip Firmware
Mitel 6940w Sip Firmware
Mitel 6970 Conference Firmware
Weaknesses CWE-88
CPEs cpe:2.3:o:mitel:6863i_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6865i_sip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6867i_sip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6869i_sip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6873i_sip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6905_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6910_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6915_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6920_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6920w_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6930_sip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6930w_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6940_sip_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6940w_sip_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6970_conference_firmware:*:*:*:*:*:*:*:*
Vendors & Products Mitel
Mitel 6863i Sip Firmware
Mitel 6865i Sip Firmware
Mitel 6867i Sip Firmware
Mitel 6869i Sip Firmware
Mitel 6873i Sip Firmware
Mitel 6905 Sip Firmware
Mitel 6910 Sip Firmware
Mitel 6915 Sip Firmware
Mitel 6920 Sip Firmware
Mitel 6920w Sip Firmware
Mitel 6930 Sip Firmware
Mitel 6930w Sip Firmware
Mitel 6940 Sip Firmware
Mitel 6940w Sip Firmware
Mitel 6970 Conference Firmware
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 17:00:00 +0000


Mon, 12 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-08-12T00:00:00

Updated: 2024-08-14T17:56:24.662Z

Reserved: 2024-07-22T00:00:00

Link: CVE-2024-41710

cve-icon Vulnrichment

Updated: 2024-08-14T17:26:41.540Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-12T19:15:16.850

Modified: 2024-08-14T18:35:06.257

Link: CVE-2024-41710

cve-icon Redhat

No data.