7.2

CVE-2024-41710

Warnung
Exploit

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitel6970 Firmware Version <= 6.4.0.136
   Mitel6970 Version-
Mitel6940w Sip Firmware Version <= 6.4.0.136
   Mitel6940w Sip Version-
Mitel6930w Sip Firmware Version <= 6.4.0.136
   Mitel6930w Sip Version-
Mitel6920w Sip Firmware Version <= 6.4.0.136
   Mitel6920w Sip Version-
Mitel6920 Sip Firmware Version <= 6.4.0.136
   Mitel6920 Sip Version-
Mitel6915 Sip Firmware Version <= 6.4.0.136
   Mitel6915 Sip Version-
Mitel6910 Sip Firmware Version <= 6.4.0.136
   Mitel6910 Sip Version-
Mitel6905 Sip Firmware Version <= 6.4.0.136
   Mitel6905 Sip Version-
Mitel6940 Sip Firmware Version <= 6.4.0.136
   Mitel6940 Sip Version-
Mitel6930 Sip Firmware Version <= 6.4.0.136
   Mitel6930 Sip Version-
Mitel6873i Sip Firmware Version <= 6.4.0.136
   Mitel6873i Sip Version-
Mitel6869i Sip Firmware Version <= 6.4.0.136
   Mitel6869i Sip Version-
Mitel6867i Sip Firmware Version <= 6.4.0.136
   Mitel6867i Sip Version-
Mitel6865i Sip Firmware Version <= 6.4.0.136
   Mitel6865i Sip Version-
Mitel6863i Sip Firmware Version <= 6.4.0.136
   Mitel6863i Sip Version-

12.02.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Mitel SIP Phones Argument Injection Vulnerability

Schwachstelle

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.68% 0.952
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.8 0.9 5.9
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.