TROYANOSYVIRUS
Back to CVEs

CVE-2024-41710

HIGHCISA KEV
7.2

Description

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

CVE Details

CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published8/12/2024
Last Modified11/5/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorMitel
ProductSIP Phones
Vulnerability NameMitel SIP Phones Argument Injection Vulnerability
KEV Date Added2025-02-12
Remediation Due Date2025-03-05
Ransomware UseUnknown

Affected Products

mitel:6863i_sipmitel:6863i_sip_firmwaremitel:6865i_sipmitel:6865i_sip_firmwaremitel:6867i_sipmitel:6867i_sip_firmwaremitel:6869i_sipmitel:6869i_sip_firmwaremitel:6873i_sipmitel:6873i_sip_firmwaremitel:6905_sipmitel:6905_sip_firmwaremitel:6910_sipmitel:6910_sip_firmwaremitel:6915_sipmitel:6915_sip_firmwaremitel:6920_sipmitel:6920_sip_firmwaremitel:6920w_sipmitel:6920w_sip_firmwaremitel:6930_sipmitel:6930_sip_firmwaremitel:6930w_sipmitel:6930w_sip_firmwaremitel:6940_sipmitel:6940_sip_firmwaremitel:6940w_sipmitel:6940w_sip_firmwaremitel:6970mitel:6970_firmware

Weaknesses (CWE)

CWE-88CWE-88

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.