CVE-2019-18863: Mitel 6863i Firmware
Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
Affected products
- Mitel 6863i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
- Mitel 6865i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
- Mitel 6867i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
- Mitel 6869i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
- Mitel 6873i Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
- Mitel 6920 Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
- Mitel 6930 Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
- Mitel 6940 Firmware: before 5.1.0.2051 (fixed in 5.1.0.2051); version 5.1.0.2051 only
Published 2020-03-02. Last modified 2026-06-17.