← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-18863

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.

No Active Exploit Signals
CVSS Base Score
5.9
MEDIUM
EPSS Probability:0.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
mitel 6863i_firmware 5.1.0.2051
mitel 6863i all
mitel 6865i_firmware 5.1.0.2051
mitel 6865i all
mitel 6867i_firmware 5.1.0.2051
mitel 6867i all
mitel 6869i_firmware 5.1.0.2051
mitel 6869i all
mitel 6873i_firmware 5.1.0.2051
mitel 6873i all
mitel 6920_firmware 5.1.0.2051
mitel 6920 all
mitel 6930_firmware 5.1.0.2051
mitel 6930 all
mitel 6940_firmware 5.1.0.2051
mitel 6940 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.513%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-11-11T00:00:00
Published2020-03-02T17:52:37
Last Updated2024-08-05T02:02:39

LINK COPIED TO CLIPBOARD