CVE-2003-20001: Infoleak

Published Apr 1, 2025
·
Updated

An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.

Affected Software

1 affected component
Mitel ICP VoIP 3100

Event History

Apr 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2003-20001?

CVE-2003-20001 is considered a moderate severity vulnerability due to the unauthorized disclosure of information.

2

How do I fix CVE-2003-20001?

To fix CVE-2003-20001, ensure that TELNET access is disabled on the Mitel ICP VoIP 3100 devices.

3

What type of information is disclosed by CVE-2003-20001?

CVE-2003-20001 discloses details about incoming calls and SMDR records during a specific login process.

4

What devices are affected by CVE-2003-20001?

CVE-2003-20001 affects Mitel ICP VoIP 3100 devices.

5

Is CVE-2003-20001 a remote or local vulnerability?

CVE-2003-20001 is a remote vulnerability, allowing external users to exploit it over the network.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203