CVE-2018-15497
9.8
CRITICAL · CVSS 3.0 · EPSS 4.9% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.87% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-10-23 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| mitel | mivoice 5330e |
| mitel | mivoice 5330e firmware |
References
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0009
- https://www.nccgroup.trust/uk/our-research/technical-advisory-mitel-mivoice-5330e-memory-corruption-flaw/
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0009
- https://www.nccgroup.trust/uk/our-research/technical-advisory-mitel-mivoice-5330e-memory-corruption-flaw/
→ the Explorer · watch your stack · NVD