CVE-2019-18863: Mitel 6863i Firmware

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.

Affected products

  • Mitel 6863i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
  • Mitel 6865i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
  • Mitel 6867i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
  • Mitel 6869i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
  • Mitel 6873i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
  • Mitel 6920 Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
  • Mitel 6930 Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
  • Mitel 6940 Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only

Published 2020-03-02. Last modified 2026-06-17.