CVE-2020-27639
Last modified
CVE-2020-27639 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitel | 6873i Sip Firmware | < 5.1.0 |
| Mitel | 6873i Sip Firmware | 5.1.0 |
| Mitel | 6930 Sip Firmware | < 5.1.0 |
| Mitel | 6930 Sip Firmware | 5.1.0 |
| Mitel | 6940 Sip Firmware | < 5.1.0 |
| Mitel | 6940 Sip Firmware | 5.1.0 |
References
- https://www.mitel.com/support/security-advisoriesVendor Advisory
- https://www.mitel.com/support/security-advisoriesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27639?
How severe is CVE-2020-27639?
How do I fix CVE-2020-27639?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27633In FNET 4.6.3, TCP ISNs are improperly random.9.1
- CVE-2020-27634In Contiki 4.5, TCP ISNs are improperly random.9.1
- CVE-2020-27635In PicoTCP 1.7.0, TCP ISNs are improperly random.9.1
- CVE-2020-27636In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random…9.1
- CVE-2020-27637The R programming language’s default package manager CRAN is…9.8
- CVE-2020-27638receive.c in fastd before v21 allows denial of service (asse…7.5
- CVE-2020-2764Vulnerability in the Java SE product of Oracle Java SE (comp…3.7
- CVE-2020-27640The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet p…8.1
- CVE-2020-27641Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-27642A cross-site scripting (XSS) vulnerability exists in the 'me…6.1
- CVE-2020-27643The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745…6.5
- CVE-2020-27644The Inventory module of the 1E Client 5.0.0.745 doesn't hand…8.8
Are you affected by CVE-2020-27639?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
