CVE-2022-29855
11.05.2022, 20:15
Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.Enginsight
Vendor | Product | Version |
---|---|---|
mitel | 6873i_sip_firmware | 𝑥 < 5.1.0.8017 |
mitel | 6873i_sip_firmware | 6.0.0.368 ≤ 𝑥 < 6.1.0.171 |
mitel | 6930_sip_firmware | 𝑥 < 5.1.0.8017 |
mitel | 6930_sip_firmware | 6.0.0.368 ≤ 𝑥 < 6.1.0.171 |
mitel | 6940_sip_firmware | 𝑥 < 5.1.0.8017 |
mitel | 6940_sip_firmware | 6.0.0.368 ≤ 𝑥 < 6.1.0.171 |
mitel | 6865i_sip_firmware | 𝑥 < 5.1.0.8017 |
mitel | 6865i_sip_firmware | 6.0.0.368 ≤ 𝑥 < 6.1.0.171 |
mitel | 6867i_sip_firmware | 𝑥 < 5.1.0.8017 |
mitel | 6867i_sip_firmware | 6.0.0.368 ≤ 𝑥 < 6.1.0.171 |
mitel | 6869i_sip_firmware | 𝑥 < 5.1.0.8017 |
mitel | 6869i_sip_firmware | 6.0.0.368 ≤ 𝑥 < 6.1.0.171 |
mitel | 6920_sip_firmware | 𝑥 ≤ 5.1.0.8016 |
mitel | 6920_sip_firmware | 6.0.0.368 ≤ 𝑥 ≤ 6.1.0.165 |
mitel | 6910_sip_firmware | 𝑥 ≤ 5.1.0.8016 |
mitel | 6910_sip_firmware | 6.0.0.368 ≤ 𝑥 ≤ 6.1.0.165 |
mitel | 6905_sip_firmware | 𝑥 ≤ 5.1.0.8016 |
mitel | 6905_sip_firmware | 6.0.0.368 ≤ 𝑥 ≤ 6.1.0.165 |
𝑥
= Vulnerable software versions
References