CVE-2018-15497: Mitel MiVoice 5330e Firmware

Critical severity, CVSS 9.8. EPSS: 4.9% chance of exploitation in the next 30 days.

The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution.

Affected products

  • Mitel MiVoice 5330e Firmware: up to and including 6.5.0.16

Published 2018-10-23. Last modified 2026-06-17.