CVE-2024-41710

HIGH CISA KEV
Published Aug 12, 2024 Modified Nov 5, 2025 CWE-88

Description

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.

CVSS v3.1 Score

7.2
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: Feb 12, 2025 Remediation due: Mar 5, 2025

Weakness Type (CWE)

CWE-88 CWE-88

Affected Products

Vendor Product
mitel 6970_firmware
mitel 6970
mitel 6940w_sip_firmware
mitel 6940w_sip
mitel 6930w_sip_firmware
mitel 6930w_sip
mitel 6920w_sip_firmware
mitel 6920w_sip
mitel 6920_sip_firmware
mitel 6920_sip
mitel 6915_sip_firmware
mitel 6915_sip
mitel 6910_sip_firmware
mitel 6910_sip
mitel 6905_sip_firmware
mitel 6905_sip
mitel 6940_sip_firmware
mitel 6940_sip
mitel 6930_sip_firmware
mitel 6930_sip
mitel 6873i_sip_firmware
mitel 6873i_sip
mitel 6869i_sip_firmware
mitel 6869i_sip
mitel 6867i_sip_firmware
mitel 6867i_sip
mitel 6865i_sip_firmware
mitel 6865i_sip
mitel 6863i_sip_firmware
mitel 6863i_sip

References

Frequently Asked Questions

What is CVE-2024-41710? +
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system. It has a CVSS v3.1 base score of 7.2 (HIGH). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2024-41710? +
CVE-2024-41710 has a CVSS v3.1 score of 7.2 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-41710? +
CVE-2024-41710 affects products from mitel, specifically: 6863i_sip, 6863i_sip_firmware, 6865i_sip, 6865i_sip_firmware, 6867i_sip, 6867i_sip_firmware, 6869i_sip, 6869i_sip_firmware, 6873i_sip, 6873i_sip_firmware, 6905_sip, 6905_sip_firmware, 6910_sip, 6910_sip_firmware, 6915_sip, 6915_sip_firmware, 6920_sip, 6920_sip_firmware, 6920w_sip, 6920w_sip_firmware, 6930_sip, 6930_sip_firmware, 6930w_sip, 6930w_sip_firmware, 6940_sip, 6940_sip_firmware, 6940w_sip, 6940w_sip_firmware, 6970, 6970_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-41710? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-41710 — free, no signup required.

Start Free Scan