peter bassill · operator
$ cve CVE-2018-15497 JSON

CVE-2018-15497

9.8
CRITICAL · CVSS 3.0 · EPSS 4.9% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.87% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2018-10-23
Last modified2026-06-17

Affected (2)

VendorProduct
mitelmivoice 5330e
mitelmivoice 5330e firmware

References

→ the Explorer  ·  watch your stack  ·  NVD