LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-41710: Mitel SIP Phones Argument Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 12, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 5, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-41710 to its Known Exploited Vulnerabilities catalog on Feb 12, 2025, with a federal patch deadline of Mar 5, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot…

CVE-2024-41710 is an argument injection vulnerability in certain Mitel SIP Phones. It stems from insufficient parameter sanitization during the boot process on Mitel 6800 Series, 6900 Series, and 6900w Series devices, including the 6970 Conference Unit. Successful exploitation may allow an attacker to execute arbitrary commands within the context of the system.

This matters for IT and security teams because SIP phones often sit on corporate voice and data networks, sometimes with elevated local privileges or network reach. Command execution on such endpoints can lead to further lateral movement, configuration tampering, or persistence if the device is not isolated. Confirm all specifics against the vendor advisory, as public detail beyond the CISA summary is limited.

How it works

The weakness is classified as CWE-88 (argument injection). In this class of flaw, untrusted or poorly sanitized input is passed as arguments to a command or process without adequate filtering or escaping. Here, the issue occurs during the boot process of the affected Mitel SIP phones due to insufficient parameter sanitization.

An attacker who can influence the relevant parameters at boot time may inject additional arguments that the system interprets as commands. This can result in arbitrary command execution in the context of the phone's system. Exact attack vectors, required access (local, network, or physical), and precise injection points are not detailed in the provided facts; treat them as general to this vulnerability class and verify against the vendor advisory. No specific exploit mechanics or proof-of-concept details are available here, so do not assume remote unauthenticated reach without confirmation.

Am I affected? How to find it in your systems

The vulnerability affects Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit. These devices typically run as desk phones, conference units, or related VoIP endpoints connected to enterprise SIP infrastructure, often managed via provisioning servers, DHCP options, or central management platforms.

How to remediate

Prioritize applying the mitigations or updates specified by Mitel in their vendor instructions for CVE-2024-41710. CISA's required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Do not rely on version numbers or patch names not listed in the facts; obtain and follow the official advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to argument injection and boot-time command risks on SIP endpoints.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to device compromise and subsequent network access that may result in data exposure, though known ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected phones, collect forensic evidence from management logs and network captures, and follow your incident response process. Readers can run a free exposure scan of their email to check known breach data for any related account compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMitel · SIP Phones
WeaknessCWE-88
Added to CISA KEVFeb 12, 2025
Federal patch deadlineMar 5, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities