8.8

CVE-2024-28066

Exploit

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
Mitel6940w Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6940w Version-
Mitel6930w Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6930w Version-
Mitel6920w Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6920w Version-
Mitel6970 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6970 Version-
Mitel6915 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6915 Version-
Mitel6910 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6910 Version-
Mitel6905 Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel6905 Version-
MitelOpenscape Cp710 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp710 Version-
MitelOpenscape Cp410 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp410 Version-
MitelOpenscape Cp210 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp210 Version-
MitelOpenscape Cp110 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cp110 Version-
MitelOpenscape Cpx10 Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Cpx10 Version-
MitelOpenscape Dect Firmware Version >= 1.10.4.3 < 1.11.3.0
   MitelOpenscape Dect Version-
Mitel700d Dect Firmware Version >= 1.10.4.3 < 1.11.3.0
   Mitel700d Dect Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.132
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1391 Use of Weak Credentials

The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.

CWE-259 Use of Hard-coded Password

The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.