CVE-2020-27639 Information
Jun 07, 2022
cve
Description
The Bluetooth handset of Mitel MiVoice 6873i 6930 and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Reference
https://www.mitel.com/support/security-advisories
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
8.1
Share on: