CVE-2024-31966
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct an argument injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to access sensitive information, modify system configuration or execute arbitrary commands.
Una vulnerabilidad en los teléfonos SIP Mitel de las series 6800 y 6900, incluida la unidad de conferencia 6970, hasta 6.3 SP3 HF4, permite a un atacante autenticado con privilegios administrativos realizar un ataque de inyección de argumentos debido a una sanitización insuficiente de los parámetros. Un exploit exitoso podría permitir a un atacante acceder a información confidencial, modificar la configuración del sistema o ejecutar comandos arbitrarios.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-04-08 CVE Reserved
- 2024-05-02 CVE Published
- 2024-08-02 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0009 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitel Search vendor "Mitel" | 6800 Series Firmware Search vendor "Mitel" for product "6800 Series Firmware" | * | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | 6900 Series Firmware Search vendor "Mitel" for product "6900 Series Firmware" | * | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | 6900w Series Firmware Search vendor "Mitel" for product "6900w Series Firmware" | * | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | 6970 Firmware Search vendor "Mitel" for product "6970 Firmware" | * | - |
Affected
|