CVE-2019-18863
Severity CVSS v4.0:
Pending analysis
Type:
CWE-326
Inadequate Encryption Strength
Publication date:
02/03/2020
Last modified:
21/07/2021
Description
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:mitel:6863i_firmware:*:*:*:*:*:*:*:* | 5.1.0.2051 (excluding) | |
cpe:2.3:o:mitel:6863i_firmware:5.1.0.2051:-:*:*:*:*:*:* | ||
cpe:2.3:o:mitel:6863i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:* | ||
cpe:2.3:h:mitel:6863i:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:mitel:6865i_firmware:*:*:*:*:*:*:*:* | 5.1.0.2051 (excluding) | |
cpe:2.3:o:mitel:6865i_firmware:5.1.0.2051:-:*:*:*:*:*:* | ||
cpe:2.3:o:mitel:6865i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:* | ||
cpe:2.3:h:mitel:6865i:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:mitel:6867i_firmware:*:*:*:*:*:*:*:* | 5.1.0.2051 (excluding) | |
cpe:2.3:o:mitel:6867i_firmware:5.1.0.2051:-:*:*:*:*:*:* | ||
cpe:2.3:o:mitel:6867i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:* | ||
cpe:2.3:h:mitel:6867i:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:mitel:6869i_firmware:*:*:*:*:*:*:*:* | 5.1.0.2051 (excluding) | |
cpe:2.3:o:mitel:6869i_firmware:5.1.0.2051:-:*:*:*:*:*:* | ||
cpe:2.3:o:mitel:6869i_firmware:5.1.0.2051:sp2_hf2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page