« Volver al listado

CVE-2020-27639

Estado: ModificadaAlta (8.1)—

The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-27639",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.8,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:P/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-18T08:15:14.937",
  "references": [
    {
      "url": "https://www.mitel.com/support/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.mitel.com/support/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. A successful exploit could allow an attacker to eavesdrop on conversations."
    },
    {
      "lang": "es",
      "value": "El auricular Bluetooth de los teléfonos SIP Mitel MiVoice 6873i, 6930 y 6940 con versiones de firmware anteriores a 5.1.0.SP6, podría permitir a un atacante no autenticado dentro del alcance de Bluetooth emparejar un dispositivo Bluetooth fraudulento cuando un teléfono pierde la conexión debido a un mecanismo de emparejamiento inapropiado. Un explotación con éxito podría permitir a un atacante espiar conversaciones"
    }
  ],
  "lastModified": "2026-06-17T03:09:25.037",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mitel:6873i_sip_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBA2C316-F64F-495E-B0F6-DF3A1CA2F7F3",
              "versionEndExcluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6873i_sip_firmware:5.1.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E332F57-29CC-4BAD-8AE4-22A7A50D7448"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6873i_sip_firmware:5.1.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B903C11-0329-4B6A-9347-296AAA39A907"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6873i_sip_firmware:5.1.0:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4298046A-48C2-43B0-BCDF-F276F895580A"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6873i_sip_firmware:5.1.0:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E13828F2-568A-4B17-93A9-7191CE6C1818"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6873i_sip_firmware:5.1.0:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A860C30B-704E-4EA3-9B33-3946ACF6F92C"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6873i_sip_firmware:5.1.0:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3817459A-F32C-4BE7-9A17-30755F801AA9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:mitel:6873i_sip:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3C298A98-C6CE-4AEB-AD9F-FFCFA1E865F6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mitel:6930_sip_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA3299CA-D225-4DAB-9729-D1C3F3148173",
              "versionEndExcluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6930_sip_firmware:5.1.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7762B8E3-F11C-4D40-A700-934C7B51D3F3"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6930_sip_firmware:5.1.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFB39FD4-1DA6-456C-A77B-DE1F1607AEF1"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6930_sip_firmware:5.1.0:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "960490B4-691F-401E-BDD3-9F8C052FD26E"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6930_sip_firmware:5.1.0:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E143054-0890-4BD4-A473-79316A013706"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6930_sip_firmware:5.1.0:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DFC51C7-A125-4D49-8EDA-A9C0E6E763BC"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6930_sip_firmware:5.1.0:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B887C52E-2C0C-400A-8A4D-83A60971CC49"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:mitel:6930_sip:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1837336E-7A1D-414C-B888-56350AF6C32A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mitel:6940_sip_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F52A992E-61C5-47BB-8DE9-FD7FDDEE9000",
              "versionEndExcluding": "5.1.0"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6940_sip_firmware:5.1.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBA83A9A-4A5D-45D3-B858-3BCE9643F576"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6940_sip_firmware:5.1.0:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17653FAC-6A90-4CB5-8715-D0AE21463BEC"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6940_sip_firmware:5.1.0:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCDC8C65-9D97-4B3E-8346-BD817CC45743"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6940_sip_firmware:5.1.0:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4DDC7F58-ACBA-4D51-904C-3309A161108F"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6940_sip_firmware:5.1.0:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10686543-0185-4C86-AD4B-378E534DE60C"
            },
            {
              "criteria": "cpe:2.3:o:mitel:6940_sip_firmware:5.1.0:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56E959AD-A7E5-474D-A576-72B5A2BF951D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:mitel:6940_sip:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "05422EAF-9528-48CE-972C-9DF111F91570"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}