ZeroHour

CVE-2019-18863

CVSS 3.1
5.9 medium
EPSS
<1%p42
Published
()
Modified
Description

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.

Vendors
mitel
Products
6863i firmware, 6865i firmware, 6867i firmware, 6869i firmware, 6873i firmware, 6920 firmware, 6930 firmware, 6940 firmware
Weakness
CWE-326
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.