CVE-2024-41711
 
Severity Score
6.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-07-22 CVE Reserved
- 2024-08-13 CVE Published
- 2024-08-14 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0020 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitel Search vendor "Mitel" | 6800 Series Sip Phones Search vendor "Mitel" for product "6800 Series Sip Phones" | * | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | 6900 Series Sip Phones Search vendor "Mitel" for product "6900 Series Sip Phones" | * | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | 6970 Conference Unit Search vendor "Mitel" for product "6970 Conference Unit" | * | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | 6900w Series Sip Phone Search vendor "Mitel" for product "6900w Series Sip Phone" | * | - |
Affected
|