CVE-2019-18863

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
02/03/2020
Last modified:
21/07/2021

Description

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mitel:6863i_firmware:*:*:*:*:*:*:*:* 5.1.0.2051 (excluding)
cpe:2.3:o:mitel:6863i_firmware:5.1.0.2051:-:*:*:*:*:*:*
cpe:2.3:o:mitel:6863i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:*
cpe:2.3:h:mitel:6863i:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6865i_firmware:*:*:*:*:*:*:*:* 5.1.0.2051 (excluding)
cpe:2.3:o:mitel:6865i_firmware:5.1.0.2051:-:*:*:*:*:*:*
cpe:2.3:o:mitel:6865i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:*
cpe:2.3:h:mitel:6865i:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6867i_firmware:*:*:*:*:*:*:*:* 5.1.0.2051 (excluding)
cpe:2.3:o:mitel:6867i_firmware:5.1.0.2051:-:*:*:*:*:*:*
cpe:2.3:o:mitel:6867i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:*
cpe:2.3:h:mitel:6867i:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6869i_firmware:*:*:*:*:*:*:*:* 5.1.0.2051 (excluding)
cpe:2.3:o:mitel:6869i_firmware:5.1.0.2051:-:*:*:*:*:*:*
cpe:2.3:o:mitel:6869i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:*