peter bassill · operator
$ cve CVE-2003-20001 JSON

CVE-2003-20001 EXPLOIT

5.6
MEDIUM · CVSS 3.1 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.

Scoring

CVSS5.6 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS1.6% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2025-04-01
Last modified2026-06-16

Public exploits

SourceTitleDate
exploit-dbMitel mitel-cs018 - Call Data Information Disclosure2020-12-02

References

→ the Explorer  ·  watch your stack  ·  NVD