CVE Feed

    Dashboard / CVE / CVE-2024-41710

    CVE-2024-41710

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

    Published:Aug 12, 2024
    Last Modified:Nov 5, 2025
    EPS:Aug 12, 2024
    EPSS Score:0.19683
    CVSS Score:6.8

    CISA Notification

    Description

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Mar 5, 2025
    555 days ago
    Alert Date
    Feb 12, 2025
    576 days ago

    Affected Products

    Vendor
    Mitel
    Product
    6863i Sip
    Vendor
    Mitel
    Product
    6863i Sip Firmware
    Vendor
    Mitel
    Product
    6865i Sip
    Vendor
    Mitel
    Product
    6865i Sip Firmware
    Vendor
    Mitel
    Product
    6867i Sip
    Vendor
    Mitel
    Product
    6867i Sip Firmware
    Vendor
    Mitel
    Product
    6869i Sip
    Vendor
    Mitel
    Product
    6869i Sip Firmware
    Vendor
    Mitel
    Product
    6873i Sip
    Vendor
    Mitel
    Product
    6873i Sip Firmware
    Vendor
    Mitel
    Product
    6905 Sip
    Vendor
    Mitel
    Product
    6905 Sip Firmware
    Vendor
    Mitel
    Product
    6910 Sip
    Vendor
    Mitel
    Product
    6910 Sip Firmware
    Vendor
    Mitel
    Product
    6915 Sip
    Vendor
    Mitel
    Product
    6915 Sip Firmware
    Vendor
    Mitel
    Product
    6920 Sip
    Vendor
    Mitel
    Product
    6920 Sip Firmware
    Vendor
    Mitel
    Product
    6920w Sip
    Vendor
    Mitel
    Product
    6920w Sip Firmware
    Vendor
    Mitel
    Product
    6930 Sip
    Vendor
    Mitel
    Product
    6930 Sip Firmware
    Vendor
    Mitel
    Product
    6930w Sip
    Vendor
    Mitel
    Product
    6930w Sip Firmware
    Vendor
    Mitel
    Product
    6940 Sip
    Vendor
    Mitel
    Product
    6940 Sip Firmware
    Vendor
    Mitel
    Product
    6940w Sip
    Vendor
    Mitel
    Product
    6940w Sip Firmware
    Vendor
    Mitel
    Product
    6970
    Vendor
    Mitel
    Product
    6970 Conference Firmware
    Vendor
    Mitel
    Product
    6970 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High