Skip to main content

Access Control Vulnerabilities in Mitel SIP Phones

Vulnerabilities in the firmware of Mitel 6800/6900 phones could allow a physical attacker to gain root privileges on the phone

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Vulnerabilities in the firmware of Mitel 6800/6900 phones could allow a physical attacker to gain root privileges on the phone


Affected platforms

The following platforms are known to be affected:

Versions: Mitel 6800 Series and 6900 Series excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 through 6.1 HF4, Mitel 6900 Series IP, versions MiNet 1.8.0.12 and earlier

Mitel SIP Phones

Threat details

Introduction

Mitel has released advisories for access control vulnerabilities affecting Mitel 6800 and 6900 products. The first vulnerability, tracked as CVE-2022-29855, affects the firmware of Mitel 6800 and 6900 desk phones. The second, CVE-2022-29854, affects Mitel 6900 Series IP (excluding 6970) using MiNet firmware.

The vulnerabilities are due to insufficient access control functionality and each has a Medium CVSS rating of 6.8. An unauthenticated attacker, with physical access to the phone, could gain high-level privileges, which could be used to access sensitive information or perform code execution in the context of the device.


Remediation advice

Affected organisations are encouraged to review Mitel Security Advisories 22-0003 and 22-0004 and apply the necessary updates.



Last edited: 27 June 2022 5:12 pm