PT-2024-29530 · Mitel · Mitel 6800 Series+2
Denys Vozniuk
·
Published
2024-08-13
·
Updated
2024-08-14
·
CVE-2024-41711
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, versions through R6.4.0.HF1 (R6.4.0.136)
Description
A vulnerability in the Mitel SIP Phones could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
Recommendations
For versions through R6.4.0.HF1 (R6.4.0.136), consider restricting physical access to the phones to minimize the risk of exploitation. As a temporary workaround, consider disabling any functionality that may be related to the argument injection vulnerability until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel 6800 Series
Mitel 6900 Series
Mitel 6970 Conference Unit