PT-2022-2956 · Mitel · Mitel 6800 Series Sip Phones+1
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mitel 6800 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier
Mitel 6800 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165)
Mitel 6900 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier
Mitel 6900 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165)
Description
The issue is related to the presence of undocumented configuration commands in the software of Mitel 6800 Series and 6900 Series SIP phones. Exploitation of this issue could allow an attacker to execute arbitrary code with root privileges and gain unauthorized access to protected information. The vulnerability is due to insufficient access control for test functionality during system startup, which could be exploited by an unauthenticated attacker with physical access to the phone.
Recommendations
For Mitel 6800 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier, update to a version later than 5.1 SP8.
For Mitel 6800 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), update to a version later than 6.1 HF4.
For Mitel 6900 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier, update to a version later than 5.1 SP8.
For Mitel 6900 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), update to a version later than 6.1 HF4.
As a temporary workaround, consider restricting physical access to the phones to minimize the risk of exploitation.
Exploit
Fix
Incorrect Authorization
Hidden Functionality
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mitel 6800 Series Sip Phones
Mitel 6900 Series Ip Phones