PT-2025-20723 · Undefined · Undefined

Published

2025-05-12

·

Updated

2025-07-23

·

CVE-2025-47187

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mitel 6800 Series SIP Phones versions through 6.4 SP4 Mitel 6900 Series SIP Phones versions through 6.4 SP4 Mitel 6900w Series SIP Phones versions through 6.4 SP4 Mitel 6970 Conference Unit versions through 6.4 SP4
Description A vulnerability exists that allows an unauthenticated attacker to perform a file upload attack due to missing authentication mechanisms. A successful exploit could allow an attacker to upload arbitrary WAV files, potentially exhausting the phone's storage. The phone's availability and operation are not affected.
Recommendations Update Mitel 6800 Series SIP Phones to a version later than 6.4 SP4. Update Mitel 6900 Series SIP Phones to a version later than 6.4 SP4. Update Mitel 6900w Series SIP Phones to a version later than 6.4 SP4. Update Mitel 6970 Conference Unit to a version later than 6.4 SP4.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-47187

Affected Products

Undefined