CVE-2024-28066
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
Affected (14)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6940w | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6930w | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6920w | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6970 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6915 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6910 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 6905 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel Openscape Cp710 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel Openscape Cp410 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel Openscape Cp210 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel Openscape Cp110 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel Openscape Cpx10 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel Openscape Dect | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.10.4.3 to 1.11.3.0 |
| Running on/with | Platform Versions |
|---|---|
Mitel 700d Dect | All versions |
Related CWEs
CWE-1391
Use of Weak Credentials
The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
CWE-259
Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
References (4)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.