CVE-2019-18863
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
Published:Mar 2, 2020
Last Modified:Nov 21, 2024
EPS:Mar 2, 2020
EPSS Score:0.00111
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Mitel
Product
6863i
Mitel
6863i
Vendor
Mitel
Product
6863i Firmware
Mitel
6863i Firmware
Vendor
Mitel
Product
6865i
Mitel
6865i
Vendor
Mitel
Product
6865i Firmware
Mitel
6865i Firmware
Vendor
Mitel
Product
6867i
Mitel
6867i
Vendor
Mitel
Product
6867i Firmware
Mitel
6867i Firmware
Vendor
Mitel
Product
6869i
Mitel
6869i
Vendor
Mitel
Product
6869i Firmware
Mitel
6869i Firmware
Vendor
Mitel
Product
6873i
Mitel
6873i
Vendor
Mitel
Product
6873i Firmware
Mitel
6873i Firmware
Vendor
Mitel
Product
6920
Mitel
6920
Vendor
Mitel
Product
6920 Firmware
Mitel
6920 Firmware
Vendor
Mitel
Product
6930
Mitel
6930
Vendor
Mitel
Product
6930 Firmware
Mitel
6930 Firmware
Vendor
Mitel
Product
6940
Mitel
6940
Vendor
Mitel
Product
6940 Firmware
Mitel
6940 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
