CVE-2024-41710: Mitel SIP Phones Argument Injection Vulnerability
Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot process. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
· high severity · unattributed attribution
Evidence and provenance
- Original source
- CISA KEV report ↗
- Published
- 2025-02-12T00:00:00Z
- Confidence basis
- No actor match
- Record ID
c0409d5a6b7e818cf05b
Vulnerabilities
CVE-2024-41710
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.