Access Control Vulnerabilities in Mitel SIP Phones
Vulnerabilities in the firmware of Mitel 6800/6900 phones could allow a physical attacker to gain root privileges on the phone
Summary
Vulnerabilities in the firmware of Mitel 6800/6900 phones could allow a physical attacker to gain root privileges on the phone
Affected platforms
The following platforms are known to be affected:
Mitel SIP Phones
Threat details
Introduction
Mitel has released advisories for access control vulnerabilities affecting Mitel 6800 and 6900 products. The first vulnerability, tracked as CVE-2022-29855, affects the firmware of Mitel 6800 and 6900 desk phones. The second, CVE-2022-29854, affects Mitel 6900 Series IP (excluding 6970) using MiNet firmware.
The vulnerabilities are due to insufficient access control functionality and each has a Medium CVSS rating of 6.8. An unauthenticated attacker, with physical access to the phone, could gain high-level privileges, which could be used to access sensitive information or perform code execution in the context of the device.
Remediation advice
Affected organisations are encouraged to review Mitel Security Advisories 22-0003 and 22-0004 and apply the necessary updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 27 June 2022 5:12 pm