First published: Fri Dec 18 2020(Updated: )
The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel 6873i Sip Firmware | <5.1.0 | |
Mitel 6873i Sip Firmware | =5.1.0 | |
Mitel 6873i Sip Firmware | =5.1.0-sp1 | |
Mitel 6873i Sip Firmware | =5.1.0-sp2 | |
Mitel 6873i Sip Firmware | =5.1.0-sp3 | |
Mitel 6873i Sip Firmware | =5.1.0-sp4 | |
Mitel 6873i Sip Firmware | =5.1.0-sp5 | |
Mitel 6873i Sip | ||
Mitel 6930 Sip Firmware | <5.1.0 | |
Mitel 6930 Sip Firmware | =5.1.0 | |
Mitel 6930 Sip Firmware | =5.1.0-sp1 | |
Mitel 6930 Sip Firmware | =5.1.0-sp2 | |
Mitel 6930 Sip Firmware | =5.1.0-sp3 | |
Mitel 6930 Sip Firmware | =5.1.0-sp4 | |
Mitel 6930 Sip Firmware | =5.1.0-sp5 | |
Mitel 6930 Sip | ||
Mitel 6940 Sip Firmware | <5.1.0 | |
Mitel 6940 Sip Firmware | =5.1.0 | |
Mitel 6940 Sip Firmware | =5.1.0-sp1 | |
Mitel 6940 Sip Firmware | =5.1.0-sp2 | |
Mitel 6940 Sip Firmware | =5.1.0-sp3 | |
Mitel 6940 Sip Firmware | =5.1.0-sp4 | |
Mitel 6940 Sip Firmware | =5.1.0-sp5 | |
Mitel 6940 Sip |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Mitel phone vulnerability is CVE-2020-27639.
The Mitel MiVoice 6873i, 6930, and 6940 SIP phones are affected by this vulnerability.
The severity of CVE-2020-27639 is high.
The impact of CVE-2020-27639 is that an unauthenticated attacker within Bluetooth range can pair a rogue Bluetooth device with the phone when the handset loses connection.
To fix the CVE-2020-27639 vulnerability, update the firmware of the Mitel MiVoice 6873i, 6930, and 6940 SIP phones to version 5.1.0.SP6 or higher.