2024-12-08 03:06:42 +00:00

64 lines
2.4 KiB
JSON

{
"id": "CVE-2024-31964",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-05-02T16:15:07.913",
"lastModified": "2024-11-21T09:14:13.567",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an attacker to modify system configuration settings and potentially cause a denial of service."
},
{
"lang": "es",
"value": "Una vulnerabilidad en los tel\u00e9fonos SIP Mitel de las series 6800 y 6900, incluida la unidad de conferencia 6970, hasta 6.3 SP3 HF4, permite a un atacante no autenticado llevar a cabo un ataque de omisi\u00f3n de autenticaci\u00f3n debido a un control de autenticaci\u00f3n inadecuado. Un exploit exitoso podr\u00eda permitir a un atacante modificar la configuraci\u00f3n del sistema y potencialmente causar una denegaci\u00f3n de servicio."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"references": [
{
"url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0007",
"source": "cve@mitre.org"
},
{
"url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0007",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}