CVE-2022-29855 - CVE House
Back to Database
Status published Medium CVE-2022-29855

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27...

Vulnerability Description

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-29855

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

6873i sip firmware, 6930 sip firmware, 6940 sip firmware, 6865i sip firmware, 6867i sip firmware, 6869i sip firmware, 6920 sip firmware, 6910 sip firmware, 6905 sip firmware
Vulnerable Versions:
0, 6.0.0.368

Timeline

Official Publish: May 11th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.