Vulnerability record · CVE-2024-41710 · published 12 August 2024
CVE-2024-41710: Mitel SIP Phones argument injection in boot process
Mitel · 6970 Firmware
Mitel 6800, 6900 and 6900w Series SIP Phones (including the 6970 Conference Unit) through R6.4.0.HF1 fail to sanitize parameters during the boot process, allowing argument injection. An attacker who already holds administrative privileges can turn that weakness into arbitrary command execution on the phone. Because the affected devices are desk phones, compromise gives a foothold on the voice network rather than a single user endpoint.
Description
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2, CISA KEV listing with a passed remediation deadline, a public exploit reference, and a 98.6th-percentile EPSS score make this a high-priority patch despite the admin-privilege requirement.
What it is
Mitel 6800, 6900 and 6900w Series SIP Phones (including the 6970 Conference Unit) through R6.4.0.HF1 fail to sanitize parameters during the boot process, allowing argument injection. An attacker who already holds administrative privileges can turn that weakness into arbitrary command execution on the phone. Because the affected devices are desk phones, compromise gives a foothold on the voice network rather than a single user endpoint.
Impact
An authenticated administrator can execute arbitrary commands in the context of the system, gaining full control of the phone's operating environment. That control can be used to alter device behavior, pivot into the voice VLAN, or tamper with communications.
Attack surface
The flaw is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires high privileges (PR:H), meaning the attacker must already be an authenticated administrative user on the device. It is not a pre-auth or remote-unauthenticated path.
Exploitation
CVE-2024-41710 is listed in CISA KEV with a 2025-02-12 addition and a 2025-03-05 remediation due date, and a public third-party exploit reference exists. EPSS is 0.41646 (98.6th percentile), indicating high predicted exploitation activity; CISA records no known ransomware campaign use.
What to do
- Upgrade affected 6800/6900/6900w Series SIP Phones and the 6970 Conference Unit to a firmware release above R6.4.0.HF1 per the Mitel advisory; if no fixed firmware is available, follow CISA guidance and discontinue use.
- Restrict administrative access to phone web/management interfaces to a dedicated management VLAN and trusted hosts only.
- Rotate and strengthen administrative credentials on all affected phones, since exploitation requires admin privilege.
- Monitor Mitel security advisory 24-0019 and CISA KEV for updated fixed versions and required actions.
- Segment voice devices from general user and server networks to limit lateral movement if a phone is compromised.
Detection
- Review phone and management logs for unexpected configuration changes or boot parameter modifications on 6800/6900/6900w devices.
- Alert on anomalous outbound connections or command execution artifacts originating from SIP phone IP addresses.
- Audit administrative logins to phone management interfaces for unusual source addresses or times.
- Inventory firmware versions across affected models and flag any device still at or below R6.4.0.HF1.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-41710 to the Known Exploited Vulnerabilities catalog on 12 February 2025 as "Mitel SIP Phones Argument Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 March 2025.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/kwburns/CVE/blob/main/Mitel/6.3.0.1020/README.md | ExploitThird Party Advisory |
| https://www.mitel.com/support/security-advisories | Vendor Advisory |
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0019 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-41710 | US Government Resource |
Track CVE-2024-41710 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-41710), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.