CVE-2024-41710

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1...

Basic Information

CVE State
PUBLISHED
Reserved Date
July 22, 2024
Published Date
August 12, 2024
Last Updated
February 13, 2025
Vendor
n/a
Product
n/a
Description
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

CVSS Scores

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2025-02-12 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-02-12 00:00:00 UTC