Vulnerability Details CVE-2022-29854
A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.6%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 7.2
Products affected by CVE-2022-29854
-
-
-
-
-
cpe:2.3:h:mitel:6930_sip:-
-
-
cpe:2.3:h:mitel:6940_sip:-
-
cpe:2.3:o:mitel:minet_firmware:-
-
cpe:2.3:o:mitel:minet_firmware:1.8.0.12