CVE-2003-20001 EXPLOIT
5.6
MEDIUM · CVSS 3.1 · EPSS 1.6% (pctl 75)
Patch early
A public exploit exists.
Description
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.
Scoring
| CVSS | 5.6 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 1.6% — more likely to be exploited than 75% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2025-04-01 |
| Last modified | 2026-06-16 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mitel mitel-cs018 - Call Data Information Disclosure | 2020-12-02 |
References
→ the Explorer · watch your stack · NVD