HIGH · 7.5

CVE-2020-13617

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory hand...

Vulnerability Description

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Mitel6863 Firmware<= 5.0
Mitel6863-
Mitel6865 Firmware<= 5.0
Mitel6865-
Mitel6867 Firmware<= 5.0
Mitel6867-
Mitel6869 Firmware<= 5.0
Mitel6869-
Mitel6873 Firmware<= 5.0
Mitel6873-
Mitel6940 Firmware<= 5.0
Mitel6940-
Mitel6970 Firmware<= 5.0
Mitel6970-
Mitel6930 Firmware<= 5.0
Mitel6930-
Mitel6920 Firmware<= 5.0
Mitel6920-
Mitel6905 Firmware<= 5.0
Mitel6905-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-13617?

CVE-2020-13617 is a vulnerability with a CVSS score of 7.5 (HIGH). The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory hand...

How severe is CVE-2020-13617?

CVE-2020-13617 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13617?

Check the references section above for vendor advisories and patch information. Affected products include: Mitel 6863 Firmware, Mitel 6863, Mitel 6865 Firmware, Mitel 6865, Mitel 6867 Firmware.