peter bassill · operator
$ cve CVE-2024-41710 JSON

CVE-2024-41710 KEV

7.2
HIGH · CVSS 3.1 · EPSS 41.6% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2025-03-05.

Description

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS41.65% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-88
On CISA KEVyes — remediate by 2025-03-05
Public exploitnone known
Published2024-08-12
Last modified2026-06-17

CISA KEV

NameMitel SIP Phones Argument Injection Vulnerability
Added2025-02-12
Due2025-03-05
Vendor / productMitel / SIP Phones
Ransomware usenone reported

Affected (30)

VendorProduct
mitel6863i sip
mitel6863i sip firmware
mitel6865i sip
mitel6865i sip firmware
mitel6867i sip
mitel6867i sip firmware
mitel6869i sip
mitel6869i sip firmware
mitel6873i sip
mitel6873i sip firmware
mitel6905 sip
mitel6905 sip firmware
mitel6910 sip
mitel6910 sip firmware
mitel6915 sip
mitel6915 sip firmware
mitel6920 sip
mitel6920 sip firmware
mitel6920w sip
mitel6920w sip firmware
mitel6930 sip
mitel6930 sip firmware
mitel6930w sip
mitel6930w sip firmware
mitel6940 sip
mitel6940 sip firmware
mitel6940w sip
mitel6940w sip firmware
mitel6970
mitel6970 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD