CVE-2020-27640: High severity mitel 6940 firmware vulnerability
The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-27640.
What is the severity level of CVE-2020-27640?
The severity level of CVE-2020-27640 is high.
Which Mitel phone models are affected by CVE-2020-27640?
The Mitel MiVoice 6940 and 6930 MiNet phones are affected by CVE-2020-27640.
What is the firmware version affected by CVE-2020-27640?
The firmware version before 1.5.3 of Mitel MiVoice 6940 and 6930 MiNet phones is affected by CVE-2020-27640.
How can an attacker exploit CVE-2020-27640?
An unauthenticated attacker within Bluetooth range can pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism, exploiting CVE-2020-27640.