5.9

CVE-2019-18863

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitel ≫ 6863i Firmware Version < 5.1.0.2051
   Mitel ≫ 6863i Version -
Mitel ≫ 6863i Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6863i Version -
Mitel ≫ 6863i Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6863i Version -
Mitel ≫ 6865i Firmware Version < 5.1.0.2051
   Mitel ≫ 6865i Version -
Mitel ≫ 6865i Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6865i Version -
Mitel ≫ 6865i Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6865i Version -
Mitel ≫ 6867i Firmware Version < 5.1.0.2051
   Mitel ≫ 6867i Version -
Mitel ≫ 6867i Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6867i Version -
Mitel ≫ 6867i Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6867i Version -
Mitel ≫ 6869i Firmware Version < 5.1.0.2051
   Mitel ≫ 6869i Version -
Mitel ≫ 6869i Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6869i Version -
Mitel ≫ 6869i Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6869i Version -
Mitel ≫ 6873i Firmware Version < 5.1.0.2051
   Mitel ≫ 6873i Version -
Mitel ≫ 6873i Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6873i Version -
Mitel ≫ 6873i Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6873i Version -
Mitel ≫ 6920 Firmware Version < 5.1.0.2051
   Mitel ≫ 6920 Version -
Mitel ≫ 6920 Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6920 Version -
Mitel ≫ 6920 Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6920 Version -
Mitel ≫ 6930 Firmware Version < 5.1.0.2051
   Mitel ≫ 6930 Version -
Mitel ≫ 6930 Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6930 Version -
Mitel ≫ 6930 Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6930 Version -
Mitel ≫ 6940 Firmware Version < 5.1.0.2051
   Mitel ≫ 6940 Version -
Mitel ≫ 6940 Firmware Version 5.1.0.2051 Update -
   Mitel ≫ 6940 Version -
Mitel ≫ 6940 Firmware Version 5.1.0.2051 Update sp2_hf2
   Mitel ≫ 6940 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.395
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

https://www.mitel.com/support/security-advisories
Vendor Advisory
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-19-0006
Vendor Advisory