8.8

CVE-2024-28066

Exploit
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitel6940w Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6940w Version-
Mitel6930w Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6930w Version-
Mitel6920w Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6920w Version-
Mitel6970 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6970 Version-
Mitel6915 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6915 Version-
Mitel6910 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6910 Version-
Mitel6905 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6905 Version-
MitelOpenscape Cp710 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp710 Version-
MitelOpenscape Cp410 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp410 Version-
MitelOpenscape Cp210 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp210 Version-
MitelOpenscape Cp110 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp110 Version-
MitelOpenscape Cpx10 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cpx10 Version-
MitelOpenscape Dect Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Dect Version-
Mitel700d Dect Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel700d Dect Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1391 Use of Weak Credentials

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

CWE-259 Use of Hard-coded Password

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

https://syss.de
Not Applicable
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt
Third Party Advisory
Exploit