CVE-2024-31964: Mitel 6800 Series SIP Phones

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an attacker to modify system configuration settings and potentially cause a denial of service.

Affected products

  • Mitel 6800 Series SIP Phones: up to and including 6.3 SP3 HF4
  • Mitel 6900w Series SIP Phone: up to and including 6.3.3
  • Mitel 6970 Conference Unit: up to and including 5.1.1 SP8

Published 2024-05-02. Last modified 2026-06-17.