CVE Vulnerabilities

CVE-2020-27640

Published: Dec 18, 2020 | Modified: Dec 22, 2020
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
4.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.

Affected Software

Name Vendor Start Version End Version
Mivoice_6940_firmware Mitel * 1.5.3 (excluding)

References