Threat intelligence report · CISA KEV

CVE-2024-41710: Mitel SIP Phones Argument Injection Vulnerability

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2025-02-12T00:00:00Z
Confidence basis
No actor match
Record ID
c0409d5a6b7e818cf05b

Vulnerabilities

CVE-2024-41710

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.