Mitel SIP phones contain an argument injection vulnerability allowing authenticated administrators to execute arbitrary commands. While these phones are network devices often deployed on corporate networks with some internet exposure, the attack vector is adjacent network and requires high privileges.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2024-08-12
Added to CISA KEV: 2025-02-12 184 DAYS BETWEEN CVE AND KEV
CVE-2024-41710 is a security vulnerability affecting various Mitel SIP phone series that can lead to unauthorized command execution with elevated privileges [2] [1].
Threat Intelligence Report CVE-2024-41710 is a critical command injection vulnerability affecting Mitel 6800, 6900, and 6900w series SIP phones, including the 6970 Conference Unit, which can lead to root access due to an input sanitization flaw. Exploitation of this vulnerability has been demonstrat…
Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. ... CVE-2024-41710 Detail. Description. A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including…
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136)…
Affected versions.Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability. Attack complexity: More severe for the least complex attacks. Privileges required: More severe if no privileges are required. User interaction: More s…