Evidence dossier
CVE-2024-41710
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an…
Exploited in the wild (CISA KEV since Feb 12, 2025). NVD reports CVSS 3.1 7.2. Severity assessments differ within at least one CVSS version. EPSS estimates 41.6% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
- State
- PUBLISHED
- Published
- Aug 12, 2024
- Updated
- Oct 21, 2025
- Evidence coverage
- 81%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Mitel SIP Phones Argument Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Mitel SIP Phones Argument Injection Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 41.65% probability · 98.58th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.416460000000; percentile 0.985780000000
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date Feb 12, 2025 · first observed Jul 19, 2026
FIRST EPSS · score date Aug 27, 2026 · 98.6th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve conflict
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
Mitel SIP Phones Argument Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Mitel SIP Phones Argument Injection Vulnerability
41.65% probability · 98.58th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.416460000000; percentile 0.985780000000
Applicability
Cited product scope
Grouped from 30 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
40 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.4.0.136"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-b076947f16c4710ae9450586223d0a2f0480409771297648bcc1c8a07ddcb825Linked exactInspect raw assertion
cpe:2.3:h:mitel:6863i_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 14 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5d7c6275-6da1-4768-a331-5290e8cb64d0
product-72fd277b901d69e1a3f452e411e6dafa47450a7093ec970b1f983f13fe00e9f6Linked exactInspect raw assertion
cpe:2.3:o:mitel:6863i_sip_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 6.4.0.136
- Match ID
10e7483a-bfb0-4f2a-b5df-43ad0a308f7b
product-c711fd0af2db09274fbdb8abcb2e85ea450ec719ac4e75af894028d2e2136611Linked exactInspect raw assertion
cpe:2.3:h:mitel:6865i_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 13 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0aaff6ed-44f6-4d3b-99ea-0f8fe58ec34b
product-7d4e9922f5d593d48b286ecb684c4c672c5e1c129117759494ac1401f364fd35Linked exactInspect raw assertion
cpe:2.3:o:mitel:6865i_sip_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 6.4.0.136
- Match ID
91cc349c-afb9-418f-9425-0038e91ef7bc
product-1bb152408e4ff651089e3f85945c10972f5674150d3efeb907cc8a2049d6bf23Linked exactInspect raw assertion
cpe:2.3:h:mitel:6867i_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4942e820-8103-4763-8715-f1301f233b05
product-5a9a45cfd640eebf84a32d5d656769ab93847ae89a3f1bd0df852730ceff64b8Linked exactInspect raw assertion
cpe:2.3:o:mitel:6867i_sip_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 6.4.0.136
- Match ID
645135a3-362e-4dbb-805c-49a6b21eb4c9
product-19213ad066335070b0bdcdf65b291523981007c991f9122bba00f0304ca782fbLinked exactInspect raw assertion
cpe:2.3:h:mitel:6869i_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
654554ed-253c-4928-92d0-92eadf5f4768
product-90c04c8d2aa17a2ac742e84e82c5be70282c79e550e2cc5e29ed4762ad05e21aLinked exactInspect raw assertion
cpe:2.3:o:mitel:6869i_sip_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 6.4.0.136
- Match ID
4415660e-385f-43dc-9f37-4c06ac7f052f
product-cddee28faeb1ce80b251a2697160d8eeed6555b15a9a4513fafb693bc4f58157Linked exactInspect raw assertion
cpe:2.3:h:mitel:6873i_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3c298a98-c6ce-4aeb-ad9f-ffcfa1e865f6
product-fa218de88b59fac9ab7917da6227bf6296b666f2cf25df985691cac575f5fbaeLinked exactInspect raw assertion
cpe:2.3:o:mitel:6873i_sip_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 6.4.0.136
- Match ID
66b0069e-b089-46b0-b1d7-c560a15fc26e
product-a89af1eba71a04e1e2b02ca987afc748048057659e7aabbf84444b31aad5aa1cLinked exactInspect raw assertion
cpe:2.3:h:mitel:6905_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97cb43cd-3b53-4839-9ae4-67024a276305
product-f6e2dd876055cb2f15dfa1246638bae972540f3377a31213fc506de17bed044aLinked exactInspect raw assertion
cpe:2.3:o:mitel:6905_sip_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 6.4.0.136
- Match ID
7b379eeb-2927-4a36-83a1-e7b4cb88f3e4
product-fe7b0752525e482ca1ceba7ffd04ea997dde8e7aafe6d4200ca011ab3edafe4fLinked exactInspect raw assertion
cpe:2.3:h:mitel:6910_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
412a5856-40b0-4633-b0f6-d87d3db85be5
product-7d46c0cc7ceb02cf863f820334f5cd6c4c166a4792fb4c36f6371bb894e32393Linked exactInspect raw assertion
cpe:2.3:o:mitel:6910_sip_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 6.4.0.136
- Match ID
91bcabb3-ba8d-41b8-953b-a33c7bfb332c
product-6d8dd6effeedea672bfc3e189d626fbbb2fb6323ab51bc179628c3acd3800be8Linked exactInspect raw assertion
cpe:2.3:h:mitel:6915_sip:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e3f279f8-83d8-4eec-aa99-5eed398653e8
Affected-product evidence
Accepted scope and product mapping
15 canonical links · 1 source-reported links
vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-074b544e095b65e4bae80295d48ece157464450ff082fd6f6d6e5b577bdea68c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fa30658d-6725-4c8a-b6bb-4f428b949c76vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-14ad18314604f0712746ad340cd913fee615acd9bbba3790e0d6bae98186f77c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
44f459aa-7152-4c0b-a6be-9f5c0d4e34c0vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-5a10109be2690bd9cfffdf99d9f85b70a8f9ce07634941a6c1cf8116b6d48d5d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fd2cde1b-e644-4017-9ce9-7e31f4da4348vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-5a9a45cfd640eebf84a32d5d656769ab93847ae89a3f1bd0df852730ceff64b8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e3120c26-2061-46ff-ac21-a00a337e63fcvendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-6b3f83fe7db4921c2ae1188b402738c1bd130065ff31bcf382b492093bddb28d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
06770786-bd3c-4dce-9fbc-11d2d4870effvendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-72fd277b901d69e1a3f452e411e6dafa47450a7093ec970b1f983f13fe00e9f6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4ef32d32-32ab-4780-9635-f9d57f072f53vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-7d46c0cc7ceb02cf863f820334f5cd6c4c166a4792fb4c36f6371bb894e32393
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7ce6141a-472c-48db-be0c-3206f80a66a6vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-7d4e9922f5d593d48b286ecb684c4c672c5e1c129117759494ac1401f364fd35
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c9587f33-835e-4d8b-a518-035f33f86c31vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-81d5fdbd42fdd6a55a3c7310d23f5082173ee8a808644f4e02fe67a5928a1f3a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e33aa612-9700-4491-a275-4942ab737d3avendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-90c04c8d2aa17a2ac742e84e82c5be70282c79e550e2cc5e29ed4762ad05e21a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1318c4f1-0bfd-430e-ad30-708e864e62e7vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-9ea9c0b041c67814c29854d0a26cf990152b40dfe82f43058a7ea58d74bb2237
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d3473fbe-90a7-40f1-aaa7-68d8ec7c911dvendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-b00a45124e7062e54af43aa054b577e599716e0b9d0abd3fe093b4a6c9128c04
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c3f5004a-aa2e-48fe-85fa-cb7e3a5bfaf8vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-e9630c982afe35c61f2c30db458f589deb90a22ada74a30af3a9884c911fff4d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d008b87a-e923-43e5-9360-782f902f29dfvendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-f6e2dd876055cb2f15dfa1246638bae972540f3377a31213fc506de17bed044a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f0b7dcb8-0654-4b00-9491-fd52d09e06d2vendor-d44338537ce24cb188b2ee221284086c801902839884a3b541f5c67b1c5b9701 · product-fa218de88b59fac9ab7917da6227bf6296b666f2cf25df985691cac575f5fbae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
52e8a743-26b3-413c-9175-2822867264f0Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 10
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2469e896-7dac-4526-9672-e8d1cc5cd3322cf56ec6-ef7e-4d21-a560-225831333dae3142aa6d-e520-42fb-8332-f3734f88051e39f73d48-0571-4df3-9ff6-e1806a085a3397987c7e-89e3-49e6-b159-6795b70cbd4699417ab1-4f22-4ca4-8918-9fa470cd65e6bb4f8608-7538-4e36-b020-861aadf74e5dd753b806-2c25-43d6-84b4-cfc0fe749c0de20ef4ab-5d88-460e-8a70-ad76638b0686eb9a633a-83b5-4c82-a902-6210747a11b1Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 6.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.