HIGH🇵🇱 Wersja polska

CVE-2024-37570

CVSS 8.8v3.1pub. 2024-06-09upd. 2024-11-21

On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Mitel 6869i Sip

    HW
    Mitel
    all versions
  • Mitel 6869i Sip Firmware

    OS
    Mitel
    4.5.0.41
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-41710HIGH7.2⚠ KEVsame product

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Confere...

CVE-2024-37569HIGH8.8same product

An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injectio...

CVE-2022-29855MEDIUM6.8same product

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerabi...

CVE-2024-41713CRITICAL9.1⚠ KEVPL ✓same vendor

Path Traversal w Mitel MiCollab — nieautoryzowany dostęp do danych

CVE-2022-29499CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w komponencie Service Appliance Mitel MiVoice Connect