CVE-2020-13617: Mitel 6863 Firmware

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.

Affected products

  • Mitel 6863 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6865 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6867 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6869 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6873 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6905 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6910 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6920 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6930 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6940 Firmware: up to and including 5.0; version 5.1 only
  • Mitel 6970 Firmware: up to and including 5.0; version 5.1 only

Published 2020-08-26. Last modified 2026-06-17.