5.9
CVSSv3

CVE-2019-18863

Published: 02/03/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and previous versions, could allow an malicious user to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the malicious user to intercept sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitel 6863i_firmware

mitel 6863i_firmware 5.1.0.2051

mitel 6865i_firmware

mitel 6865i_firmware 5.1.0.2051

mitel 6867i_firmware

mitel 6867i_firmware 5.1.0.2051

mitel 6869i_firmware

mitel 6869i_firmware 5.1.0.2051

mitel 6873i_firmware

mitel 6873i_firmware 5.1.0.2051

mitel 6920_firmware

mitel 6920_firmware 5.1.0.2051

mitel 6930_firmware

mitel 6930_firmware 5.1.0.2051

mitel 6940_firmware

mitel 6940_firmware 5.1.0.2051