PT-2022-2956 · Mitel · Mitel 6800 Series Sip Phones+1

·

CVE-2022-29855

·

Published

2022-02-23

·

Updated

2023-08-08

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mitel 6800 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier Mitel 6800 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165) Mitel 6900 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier Mitel 6900 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165)
Description The issue is related to the presence of undocumented configuration commands in the software of Mitel 6800 Series and 6900 Series SIP phones. Exploitation of this issue could allow an attacker to execute arbitrary code with root privileges and gain unauthorized access to protected information. The vulnerability is due to insufficient access control for test functionality during system startup, which could be exploited by an unauthenticated attacker with physical access to the phone.
Recommendations For Mitel 6800 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier, update to a version later than 5.1 SP8. For Mitel 6800 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), update to a version later than 6.1 HF4. For Mitel 6900 Series SIP Phones versions 5.1 SP8 (5.1.0.8016) and earlier, update to a version later than 5.1 SP8. For Mitel 6900 Series SIP Phones versions 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), update to a version later than 6.1 HF4. As a temporary workaround, consider restricting physical access to the phones to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Hidden Functionality

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03566
CVE-2022-29855

Affected Products

Mitel 6800 Series Sip Phones
Mitel 6900 Series Ip Phones