CVE-2020-13617
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.
Affected (66)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6863 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6865 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6867 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6869 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6873 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6940 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6970 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6930 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6920 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6905 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6910 | All versions |
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.