Lucene search

K
cve[email protected]CVE-2020-13617
HistoryAug 26, 2020 - 6:15 p.m.

CVE-2020-13617

2020-08-2618:15:10
CWE-307
web.nvd.nist.gov
24
mitel
mivoice
6800 series
6900 series
sip phones
firmware
cve-2020-13617
security vulnerability
information exposure
memory handling
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.2%

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

Affected configurations

NVD
Node
mitel6863Match-
AND
mitel6863_firmwareRange5.0
OR
mitel6863_firmwareMatch5.1-
OR
mitel6863_firmwareMatch5.1sp1
OR
mitel6863_firmwareMatch5.1sp2
OR
mitel6863_firmwareMatch5.1sp3
OR
mitel6863_firmwareMatch5.1sp4
Node
mitel6865Match-
AND
mitel6865_firmwareRange5.0
OR
mitel6865_firmwareMatch5.1-
OR
mitel6865_firmwareMatch5.1sp1
OR
mitel6865_firmwareMatch5.1sp2
OR
mitel6865_firmwareMatch5.1sp3
OR
mitel6865_firmwareMatch5.1sp4
Node
mitel6867Match-
AND
mitel6867_firmwareRange5.0
OR
mitel6867_firmwareMatch5.1-
OR
mitel6867_firmwareMatch5.1sp1
OR
mitel6867_firmwareMatch5.1sp2
OR
mitel6867_firmwareMatch5.1sp3
OR
mitel6867_firmwareMatch5.1sp4
Node
mitel6869Match-
AND
mitel6869_firmwareRange5.0
OR
mitel6869_firmwareMatch5.1-
OR
mitel6869_firmwareMatch5.1sp1
OR
mitel6869_firmwareMatch5.1sp2
OR
mitel6869_firmwareMatch5.1sp3
OR
mitel6869_firmwareMatch5.1sp4
Node
mitel6873Match-
AND
mitel6873_firmwareRange5.0
OR
mitel6873_firmwareMatch5.1-
OR
mitel6873_firmwareMatch5.1sp1
OR
mitel6873_firmwareMatch5.1sp2
OR
mitel6873_firmwareMatch5.1sp3
OR
mitel6873_firmwareMatch5.1sp4
Node
mitel6940Match-
AND
mitel6940_firmwareRange5.0
OR
mitel6940_firmwareMatch5.1-
OR
mitel6940_firmwareMatch5.1sp1
OR
mitel6940_firmwareMatch5.1sp2
OR
mitel6940_firmwareMatch5.1sp3
OR
mitel6940_firmwareMatch5.1sp4
Node
mitel6970Match-
AND
mitel6970_firmwareRange5.0
OR
mitel6970_firmwareMatch5.1-
OR
mitel6970_firmwareMatch5.1sp1
OR
mitel6970_firmwareMatch5.1sp2
OR
mitel6970_firmwareMatch5.1sp3
OR
mitel6970_firmwareMatch5.1sp4
Node
mitel6930Match-
AND
mitel6930_firmwareRange5.0
OR
mitel6930_firmwareMatch5.1-
OR
mitel6930_firmwareMatch5.1sp1
OR
mitel6930_firmwareMatch5.1sp2
OR
mitel6930_firmwareMatch5.1sp3
OR
mitel6930_firmwareMatch5.1sp4
Node
mitel6920_firmwareRange5.0
OR
mitel6920_firmwareMatch5.1-
OR
mitel6920_firmwareMatch5.1sp1
OR
mitel6920_firmwareMatch5.1sp2
OR
mitel6920_firmwareMatch5.1sp3
OR
mitel6920_firmwareMatch5.1sp4
AND
mitel6920Match-
Node
mitel6905_firmwareRange5.0
OR
mitel6905_firmwareMatch5.1-
OR
mitel6905_firmwareMatch5.1sp1
OR
mitel6905_firmwareMatch5.1sp2
OR
mitel6905_firmwareMatch5.1sp3
OR
mitel6905_firmwareMatch5.1sp4
AND
mitel6905Match-
Node
mitel6910_firmwareRange5.0
OR
mitel6910_firmwareMatch5.1-
OR
mitel6910_firmwareMatch5.1sp1
OR
mitel6910_firmwareMatch5.1sp2
OR
mitel6910_firmwareMatch5.1sp3
OR
mitel6910_firmwareMatch5.1sp4
AND
mitel6910Match-

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.2%

Related for CVE-2020-13617