CVE-2024-41710: Mitel SIP Phones Argument Injection Vulnerability

Published Aug 12, 2024
·
Updated

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

Other sources

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.

CISA

Affected Software

35 affected components
Mitel 6800 Series SIP Phones<=R6.4.0.HF1
Mitel 6900 Series SIP Phones<=R6.4.0.HF1
Mitel 6900w Series SIP Phones<=R6.4.0.HF1
Mitel 6970 Conference Unit<=R6.4.0.HF1
Mitel SIP Phones
All of the following
Mitel 6970 Firmware<=6.4.0.136
Mitel 6970
All of the following
Mitel 6940w Sip Firmware<=6.4.0.136
Mitel 6940w Sip
All of the following
Mitel 6930w Sip Firmware<=6.4.0.136
Mitel 6930w Sip
All of the following
Mitel 6920w Sip Firmware<=6.4.0.136
Mitel 6920w Sip
All of the following
Mitel 6920 Sip Firmware<=6.4.0.136
Mitel 6920 Sip
All of the following
Mitel 6915 Sip Firmware<=6.4.0.136
Mitel 6915 Sip
All of the following
Mitel 6910 Sip Firmware<=6.4.0.136
Mitel 6910 Sip
All of the following
Mitel 6905 Sip Firmware<=6.4.0.136
Mitel 6905 Sip
All of the following
Mitel 6940 Sip Firmware<=6.4.0.136
Mitel 6940 SIP
All of the following
Mitel 6930 Sip Firmware<=6.4.0.136
Mitel 6930 Sip
All of the following
Mitel 6873i Sip Firmware<=6.4.0.136
Mitel 6873i Sip
All of the following
Mitel 6869i Sip Firmware<=6.4.0.136
Mitel 6869i Sip
All of the following
Mitel 6867i Sip Firmware<=6.4.0.136
Mitel 6867i Sip
All of the following
Mitel 6865i Sip Firmware<=6.4.0.136
Mitel 6865i Sip
All of the following
Mitel 6863i Sip Firmware<=6.4.0.136
Mitel 6863i Sip

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Discontinue use of Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, if vendor mitigations are unavailable.

Event History

Aug 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 29, 2025
News Published
via The Register·03:32 PM
News Published
via The Register·03:36 PM
News Published
via Dark Reading·06:03 PM
News Published
via Dark Reading·06:05 PM
Jan 30, 2025
News Published
via BleepingComputer·12:55 AM
News Published
via BleepingComputer·12:57 AM
Feb 12, 2025
Known Exploited
via CISA·12:00 AM

Peer vulnerabilities

Found alongside the following vulnerabilities.

Frequently Asked Questions

1

What is the severity of CVE-2024-41710?

CVE-2024-41710 has been rated as a high-risk vulnerability due to the potential for argument injection attacks.

2

How do I fix CVE-2024-41710?

To remediate CVE-2024-41710, ensure your Mitel 6800 Series, 6900 Series, or 6970 Conference Unit is updated to the latest firmware version beyond R6.4.0.HF1.

3

Who is affected by CVE-2024-41710?

CVE-2024-41710 affects users of Mitel 6800 Series, 6900 Series, and 6970 Conference Unit SIP Phones up to version R6.4.0.HF1.

4

What type of attack is possible with CVE-2024-41710?

An authenticated attacker with administrative privileges could conduct an argument injection attack due to insufficient parameter sanitization.

5

What products does CVE-2024-41710 impact?

CVE-2024-41710 impacts the Mitel 6800 Series, 6900 Series, 6900w Series SIP Phones, and the Mitel 6970 Conference Unit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203