CVE-2020-13617

HIGH

Mitel MiVoice 6800/6900 SIP Phones <5.1.0.SP5 - Unauthenticated Sensitive Info Exposure

Title source: llm
STIX 2.1

Description

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0115
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-307
Status published
Products (17)
mitel/6863_firmware 5.1 (5 CPE variants)
mitel/6863_firmware < 5.0
mitel/6865_firmware 5.1 (5 CPE variants)
mitel/6865_firmware < 5.0
mitel/6867_firmware 5.1 (5 CPE variants)
mitel/6867_firmware < 5.0
mitel/6869_firmware 5.1 (5 CPE variants)
mitel/6869_firmware < 5.0
mitel/6873_firmware 5.1 (5 CPE variants)
mitel/6873_firmware < 5.0
... and 7 more
Published Aug 26, 2020
Tracked Since Feb 18, 2026