CVE Vulnerabilities

CVE-2020-27639

Published: Dec 18, 2020 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
4.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.

Affected Software

NameVendorStart VersionEnd Version
6873i_sip_firmwareMitel*5.1.0 (excluding)
6873i_sip_firmwareMitel5.1.0 (including)5.1.0 (including)
6873i_sip_firmwareMitel5.1.0-sp1 (including)5.1.0-sp1 (including)
6873i_sip_firmwareMitel5.1.0-sp2 (including)5.1.0-sp2 (including)
6873i_sip_firmwareMitel5.1.0-sp3 (including)5.1.0-sp3 (including)
6873i_sip_firmwareMitel5.1.0-sp4 (including)5.1.0-sp4 (including)
6873i_sip_firmwareMitel5.1.0-sp5 (including)5.1.0-sp5 (including)

References