PT-2025-20723 · Undefined · Undefined
Published
2025-05-12
·
Updated
2025-07-23
·
CVE-2025-47187
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mitel 6800 Series SIP Phones versions through 6.4 SP4
Mitel 6900 Series SIP Phones versions through 6.4 SP4
Mitel 6900w Series SIP Phones versions through 6.4 SP4
Mitel 6970 Conference Unit versions through 6.4 SP4
Description
A vulnerability exists that allows an unauthenticated attacker to perform a file upload attack due to missing authentication mechanisms. A successful exploit could allow an attacker to upload arbitrary WAV files, potentially exhausting the phone's storage. The phone's availability and operation are not affected.
Recommendations
Update Mitel 6800 Series SIP Phones to a version later than 6.4 SP4.
Update Mitel 6900 Series SIP Phones to a version later than 6.4 SP4.
Update Mitel 6900w Series SIP Phones to a version later than 6.4 SP4.
Update Mitel 6970 Conference Unit to a version later than 6.4 SP4.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined