CVE-2024-41710
HIGH CISA KEVDescription
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mitel | 6970_firmware |
| mitel | 6970 |
| mitel | 6940w_sip_firmware |
| mitel | 6940w_sip |
| mitel | 6930w_sip_firmware |
| mitel | 6930w_sip |
| mitel | 6920w_sip_firmware |
| mitel | 6920w_sip |
| mitel | 6920_sip_firmware |
| mitel | 6920_sip |
| mitel | 6915_sip_firmware |
| mitel | 6915_sip |
| mitel | 6910_sip_firmware |
| mitel | 6910_sip |
| mitel | 6905_sip_firmware |
| mitel | 6905_sip |
| mitel | 6940_sip_firmware |
| mitel | 6940_sip |
| mitel | 6930_sip_firmware |
| mitel | 6930_sip |
| mitel | 6873i_sip_firmware |
| mitel | 6873i_sip |
| mitel | 6869i_sip_firmware |
| mitel | 6869i_sip |
| mitel | 6867i_sip_firmware |
| mitel | 6867i_sip |
| mitel | 6865i_sip_firmware |
| mitel | 6865i_sip |
| mitel | 6863i_sip_firmware |
| mitel | 6863i_sip |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-41710? +
How severe is CVE-2024-41710? +
What products are affected by CVE-2024-41710? +
How do I check if I'm vulnerable to CVE-2024-41710? +
Related Vulnerabilities
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A …
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows …
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects …
XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command …
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a …