CVE-2024-28066

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mitel:6940w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6940w:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mitel:6930w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6930w:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitel:6920w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6920w:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mitel:6970_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6970:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mitel:6915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6915:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mitel:6910_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6910:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mitel:6905_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6905:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mitel:openscape_cp710_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp710:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mitel:openscape_cp410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp410:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:mitel:openscape_cp210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp210:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:mitel:openscape_cp110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp110:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:mitel:openscape_cpx10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cpx10:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:mitel:openscape_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_dect:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:mitel:700d_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:700d_dect:-:*:*:*:*:*:*:*

History

18 Jun 2025, 19:01

Type Values Removed Values Added
References () https://syss.de - () https://syss.de - Not Applicable
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt - Third Party Advisory, Exploit
First Time Mitel 700d Dect Firmware
Mitel 6940w
Mitel openscape Cp410 Firmware
Mitel 6940w Firmware
Mitel 6920w
Mitel openscape Cpx10 Firmware
Mitel openscape Cp210 Firmware
Mitel
Mitel openscape Cp410
Mitel 6970 Firmware
Mitel 700d Dect
Mitel 6930w Firmware
Mitel 6905 Firmware
Mitel openscape Cp110
Mitel openscape Dect
Mitel openscape Cp210
Mitel openscape Cpx10
Mitel 6915
Mitel 6905
Mitel 6915 Firmware
Mitel 6920w Firmware
Mitel openscape Dect Firmware
Mitel 6930w
Mitel 6910
Mitel openscape Cp710
Mitel openscape Cp110 Firmware
Mitel 6910 Firmware
Mitel openscape Cp710 Firmware
Mitel 6970
CPE cpe:2.3:h:mitel:6910:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp710_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp210:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:700d_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:700d_dect:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cpx10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6905:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6920w:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_dect:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp710:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6920w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6940w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6930w:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp410:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6940w:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6970:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6970_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6905_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cpx10:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6915:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6910_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6930w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp110:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp210_firmware:*:*:*:*:*:*:*:*

21 Nov 2024, 09:05

Type Values Removed Values Added
References () https://syss.de - () https://syss.de -
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt -

15 Aug 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-1391
CWE-259

08 Apr 2024, 18:48

Type Values Removed Values Added
Summary
  • (es) En el firmware 1.10.4.3 de Unify CP IP Phone, se utilizan credenciales débiles (una contraseña raíz codificada).

08 Apr 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-08 13:15

Updated : 2025-06-18 19:01


NVD link : CVE-2024-28066

Mitre link : CVE-2024-28066

CVE.ORG link : CVE-2024-28066


JSON object : View

Products Affected

mitel

  • 6915_firmware
  • 6910
  • 6940w
  • 6970
  • 6970_firmware
  • openscape_dect
  • 700d_dect
  • openscape_cp410_firmware
  • openscape_cp210_firmware
  • 6940w_firmware
  • 6905
  • 6930w_firmware
  • openscape_cp110_firmware
  • 6920w
  • 6915
  • openscape_cp110
  • 6910_firmware
  • openscape_cpx10_firmware
  • openscape_dect_firmware
  • openscape_cp210
  • 6920w_firmware
  • 6930w
  • openscape_cp710
  • openscape_cpx10
  • 700d_dect_firmware
  • 6905_firmware
  • openscape_cp710_firmware
  • openscape_cp410
CWE
CWE-259

Use of Hard-coded Password

CWE-1391