CVE-2020-27640

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2020
Last modified:
22/12/2020

Description

The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mitel:mivoice_6940_firmware:*:*:*:*:*:*:*:* 1.5.3 (excluding)
cpe:2.3:h:mitel:mivoice_6940:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:mivoice_6930_firmware:*:*:*:*:*:*:*:* 1.5.3 (excluding)
cpe:2.3:h:mitel:mivoice_6930:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools