CVE-2020-13617

HIGHCVSS 7.5/10EPSS 1.15%

Last modified

CVE-2020-13617 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.. EPSS estimates a 1.15% chance of exploitation in the next 30 days.

Description

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.15%

62.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Mitel6863 Firmware<= 5.0
Mitel6863 Firmware5.1
Mitel6865 Firmware<= 5.0
Mitel6865 Firmware5.1
Mitel6867 Firmware<= 5.0
Mitel6867 Firmware5.1
Mitel6869 Firmware<= 5.0
Mitel6869 Firmware5.1
Mitel6873 Firmware<= 5.0
Mitel6873 Firmware5.1
Mitel6940 Firmware<= 5.0
Mitel6940 Firmware5.1
Mitel6970 Firmware<= 5.0
Mitel6970 Firmware5.1
Mitel6930 Firmware<= 5.0
Mitel6930 Firmware5.1
Mitel6920 Firmware<= 5.0
Mitel6920 Firmware5.1
Mitel6905 Firmware<= 5.0
Mitel6905 Firmware5.1
Mitel6910 Firmware<= 5.0
Mitel6910 Firmware5.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-13617?
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.
How severe is CVE-2020-13617?
CVE-2020-13617 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.15% probability of exploitation in the next 30 days.
How do I fix CVE-2020-13617?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-13617?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST