Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4f6f-x4m3-rhqj

Опубликовано: 12 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

EPSS

Процентиль: 57%
0.00354
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.8
nvd
больше 3 лет назад

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

CVSS3: 6.8
fstec
почти 4 года назад

Уязвимость микропрограммного обеспечения настольных телефонов Mitel 6800 Series SIP Phones и 6900 Series SIP Phones, связанная с наличием недокументированных команд конфигурации, позволяющая нарушителю выполнить произвольный код с привилегиями root, а так же получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 57%
0.00354
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-863