CVE-2024-28066

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
mitel6940w_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitel6930w_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitel6920w_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitel6970_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitel6915_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitel6910_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitel6905_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitelopenscape_cp710_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitelopenscape_cp410_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitelopenscape_cp210_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitelopenscape_cp110_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitelopenscape_cpx10_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitelopenscape_dect_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
mitel700d_dect_firmware
1.10.4.3 ≤
𝑥
< 1.11.3.0
𝑥
= Vulnerable software versions