HIGH · 8.8

CVE-2024-28066

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

Vulnerability Description

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Mitel6940W Firmware>= 1.10.4.3, < 1.11.3.0
Mitel6940W-
Mitel6930W Firmware>= 1.10.4.3, < 1.11.3.0
Mitel6930W-
Mitel6920W Firmware>= 1.10.4.3, < 1.11.3.0
Mitel6920W-
Mitel6970 Firmware>= 1.10.4.3, < 1.11.3.0
Mitel6970-
Mitel6915 Firmware>= 1.10.4.3, < 1.11.3.0
Mitel6915-
Mitel6910 Firmware>= 1.10.4.3, < 1.11.3.0
Mitel6910-
Mitel6905 Firmware>= 1.10.4.3, < 1.11.3.0
Mitel6905-
MitelOpenscape Cp710 Firmware>= 1.10.4.3, < 1.11.3.0
MitelOpenscape Cp710-
MitelOpenscape Cp410 Firmware>= 1.10.4.3, < 1.11.3.0
MitelOpenscape Cp410-
MitelOpenscape Cp210 Firmware>= 1.10.4.3, < 1.11.3.0
MitelOpenscape Cp210-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-28066?

CVE-2024-28066 is a vulnerability with a CVSS score of 8.8 (HIGH). In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

How severe is CVE-2024-28066?

CVE-2024-28066 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-28066?

Check the references section above for vendor advisories and patch information. Affected products include: Mitel 6940W Firmware, Mitel 6940W, Mitel 6930W Firmware, Mitel 6930W, Mitel 6920W Firmware.