SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2003-20001

When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system.

MEDIUM 5.6EPSS 1.58%

Does this matter?

Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The information provided includes the service type, extension number and other parameters, related to the call activity.

CVSS 3.1
5.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
1.58% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-200
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.