CVE-2020-27639: High severity mitel 6873i firmware vulnerability
The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mitel phone vulnerability?
The vulnerability ID for this Mitel phone vulnerability is CVE-2020-27639.
Which Mitel SIP phone models are affected by this vulnerability?
The Mitel MiVoice 6873i, 6930, and 6940 SIP phones are affected by this vulnerability.
What is the severity of CVE-2020-27639?
The severity of CVE-2020-27639 is high.
What is the impact of CVE-2020-27639?
The impact of CVE-2020-27639 is that an unauthenticated attacker within Bluetooth range can pair a rogue Bluetooth device with the phone when the handset loses connection.
How can I fix the CVE-2020-27639 vulnerability?
To fix the CVE-2020-27639 vulnerability, update the firmware of the Mitel MiVoice 6873i, 6930, and 6940 SIP phones to version 5.1.0.SP6 or higher.