NA

CVE-2024-31966

Published: 02/05/2024 Updated: 03/05/2024

Vulnerability Summary

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones up to and including 6.3 SP3 HF4, 6900w Series SIP Phone up to and including 6.3.3, and 6970 Conference Unit up to and including 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct an argument injection attack due to insufficient parameter sanitization. A successful exploit could allow an malicious user to access sensitive information, modify system configuration or execute arbitrary commands.