SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-13617

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

HIGH 7.5EPSS 1.33%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.33% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-307
Affected
mitel/6863 firmware · mitel/6865 firmware · mitel/6867 firmware · mitel/6869 firmware · mitel/6873 firmware · mitel/6940 firmware · mitel/6970 firmware · mitel/6930 firmware · mitel/6920 firmware · mitel/6905 firmware · mitel/6910 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.