← Back to CVE List
Vulnerability Intelligence Report
Mitel SIP Phones Argument Injection Vulnerability

CVE-2024-41710

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
6.8
MEDIUM
Exploitability:1.0
Impact Score:5.9
EPSS Probability:41.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-88 ↗CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Affected Products & Versions

Vendor Product Affected Versions
mitel 6970_firmware all
mitel 6970 all
mitel 6940w_sip_firmware all
mitel 6940w_sip all
mitel 6930w_sip_firmware all
mitel 6930w_sip all
mitel 6920w_sip_firmware all
mitel 6920w_sip all
mitel 6920_sip_firmware all
mitel 6920_sip all
mitel 6915_sip_firmware all
mitel 6915_sip all
mitel 6910_sip_firmware all
mitel 6910_sip all
mitel 6905_sip_firmware all
mitel 6905_sip all
mitel 6940_sip_firmware all
mitel 6940_sip all
mitel 6930_sip_firmware all
mitel 6930_sip all
mitel 6873i_sip_firmware all
mitel 6873i_sip all
mitel 6869i_sip_firmware all
mitel 6869i_sip all
mitel 6867i_sip_firmware all
mitel 6867i_sip all
mitel 6865i_sip_firmware all
mitel 6865i_sip all
mitel 6863i_sip_firmware all
mitel 6863i_sip all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
41.201%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2024-07-22T00:00:00
Published2024-08-12T00:00:00
Last Updated2025-10-21T22:55:48

LINK COPIED TO CLIPBOARD