A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
History

Wed, 14 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mitel
Mitel 6800 Series Sip Phones
Mitel 6900 Series Sip Phones
Mitel 6900w Series Sip Phone
Mitel 6970 Conference Unit
Weaknesses CWE-88
CPEs cpe:2.3:a:mitel:6800_series_sip_phones:*:*:*:*:*:*:*:*
cpe:2.3:a:mitel:6900_series_sip_phones:*:*:*:*:*:*:*:*
cpe:2.3:a:mitel:6970_conference_unit:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6900w_series_sip_phone:*:*:*:*:*:*:*:*
Vendors & Products Mitel
Mitel 6800 Series Sip Phones
Mitel 6900 Series Sip Phones
Mitel 6900w Series Sip Phone
Mitel 6970 Conference Unit
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-08-13T00:00:00

Updated: 2024-08-14T15:41:44.554Z

Reserved: 2024-07-22T00:00:00

Link: CVE-2024-41711

cve-icon Vulnrichment

Updated: 2024-08-14T15:40:52.147Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-13T17:15:24.237

Modified: 2024-08-14T16:35:15.033

Link: CVE-2024-41711

cve-icon Redhat

No data.