CVE-2019-18863: Weak Encryption
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18863?
CVE-2019-18863 is a key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier.
How does CVE-2019-18863 affect Mitel 6800 and 6900 SIP series phones?
CVE-2019-18863 allows an attacker to launch a man-in-the-middle attack when SRTP is used in a call.
What is the severity of CVE-2019-18863?
CVE-2019-18863 has a severity rating of 5.9 (medium).
How can I fix CVE-2019-18863?
To fix CVE-2019-18863, update Mitel 6800 and 6900 SIP series phones to version 5.1.0.2051 SP2 or later.
Where can I find more information about CVE-2019-18863?
You can find more information about CVE-2019-18863 on the Mitel support website.