6.8
CVSSv3

CVE-2022-29854

Published: 13/05/2022 Updated: 29/10/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and previous versions, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitel minet_firmware

Exploits

Mitel 6800/6900 Series SIP Phones excluding 6970 and Mitel 6900 Series IP (MiNet) Phones have a flow to spawn a telnet backdoor on the device with a static root password enabled Affected versions include Rel 51 SP8 (5108016) and earlier, Rel 60 (600368) to 61 HF4 (610165), and MiNet 18012 and earlier ...