CVE Vulnerabilities

CVE-2020-27639

Published: Dec 18, 2020 | Modified: Dec 21, 2020
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
4.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.

Affected Software

Name Vendor Start Version End Version
6873i_sip_firmware Mitel * 5.1.0 (excluding)
6873i_sip_firmware Mitel 5.1.0 (including) 5.1.0 (including)
6873i_sip_firmware Mitel 5.1.0-sp1 (including) 5.1.0-sp1 (including)
6873i_sip_firmware Mitel 5.1.0-sp2 (including) 5.1.0-sp2 (including)
6873i_sip_firmware Mitel 5.1.0-sp3 (including) 5.1.0-sp3 (including)
6873i_sip_firmware Mitel 5.1.0-sp4 (including) 5.1.0-sp4 (including)
6873i_sip_firmware Mitel 5.1.0-sp5 (including) 5.1.0-sp5 (including)

References