5.9

CVE-2019-18863

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitel6863i Firmware Version < 5.1.0.2051
   Mitel6863i Version-
Mitel6863i Firmware Version5.1.0.2051 Update-
   Mitel6863i Version-
Mitel6863i Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6863i Version-
Mitel6865i Firmware Version < 5.1.0.2051
   Mitel6865i Version-
Mitel6865i Firmware Version5.1.0.2051 Update-
   Mitel6865i Version-
Mitel6865i Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6865i Version-
Mitel6867i Firmware Version < 5.1.0.2051
   Mitel6867i Version-
Mitel6867i Firmware Version5.1.0.2051 Update-
   Mitel6867i Version-
Mitel6867i Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6867i Version-
Mitel6869i Firmware Version < 5.1.0.2051
   Mitel6869i Version-
Mitel6869i Firmware Version5.1.0.2051 Update-
   Mitel6869i Version-
Mitel6869i Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6869i Version-
Mitel6873i Firmware Version < 5.1.0.2051
   Mitel6873i Version-
Mitel6873i Firmware Version5.1.0.2051 Update-
   Mitel6873i Version-
Mitel6873i Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6873i Version-
Mitel6920 Firmware Version < 5.1.0.2051
   Mitel6920 Version-
Mitel6920 Firmware Version5.1.0.2051 Update-
   Mitel6920 Version-
Mitel6920 Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6920 Version-
Mitel6930 Firmware Version < 5.1.0.2051
   Mitel6930 Version-
Mitel6930 Firmware Version5.1.0.2051 Update-
   Mitel6930 Version-
Mitel6930 Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6930 Version-
Mitel6940 Firmware Version < 5.1.0.2051
   Mitel6940 Version-
Mitel6940 Firmware Version5.1.0.2051 Update-
   Mitel6940 Version-
Mitel6940 Firmware Version5.1.0.2051 Updatesp2_hf2
   Mitel6940 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.395
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

https://www.mitel.com/support/security-advisories
Vendor Advisory
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-19-0006
Vendor Advisory