Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 5, 2025

CVE-2024-41710

High
EPSS 19.7%CISA KEV
Mitel/SIP Phones

Description

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.

EPSS — Exploit Probability

19.7%

Higher than 95.3% of all CVEs

Required Action

https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin_24-0019-001-v2.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2024-41710

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
19.7%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Feb 12, 2025

Added to KEV

Feb 12, 2025

Remediation Due

Mar 5, 2025

Affected Product

Mitel

SIP Phones

View all Mitel CVEs