CVE-2024-28066

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mitel:6940w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6940w:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mitel:6930w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6930w:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitel:6920w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6920w:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mitel:6970_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6970:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mitel:6915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6915:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mitel:6910_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6910:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mitel:6905_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6905:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mitel:openscape_cp710_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp710:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mitel:openscape_cp410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp410:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:mitel:openscape_cp210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp210:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:mitel:openscape_cp110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp110:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:mitel:openscape_cpx10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cpx10:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:mitel:openscape_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_dect:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:mitel:700d_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:700d_dect:-:*:*:*:*:*:*:*

History

18 Jun 2025, 19:01

Type Values Removed Values Added
First Time Mitel openscape Cp110
Mitel 6930w
Mitel 700d Dect Firmware
Mitel openscape Cpx10
Mitel 6940w
Mitel 6910 Firmware
Mitel 6930w Firmware
Mitel 6970
Mitel openscape Cp210
Mitel openscape Cpx10 Firmware
Mitel 6970 Firmware
Mitel 6915 Firmware
Mitel 6910
Mitel openscape Dect
Mitel openscape Cp210 Firmware
Mitel openscape Cp410 Firmware
Mitel 6905
Mitel openscape Dect Firmware
Mitel 6920w Firmware
Mitel 6940w Firmware
Mitel 6920w
Mitel 6915
Mitel openscape Cp110 Firmware
Mitel openscape Cp710
Mitel 6905 Firmware
Mitel
Mitel openscape Cp710 Firmware
Mitel 700d Dect
Mitel openscape Cp410
CPE cpe:2.3:h:mitel:6910:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_dect:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6910_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp710:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp110:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6915:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6920w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6930w:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6940w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6940w:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6930w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:700d_dect_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:700d_dect:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6970_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6970:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp410:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cpx10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cp210:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:6905_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:openscape_cpx10:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6905:-:*:*:*:*:*:*:*
cpe:2.3:h:mitel:6920w:-:*:*:*:*:*:*:*
cpe:2.3:o:mitel:openscape_cp710_firmware:*:*:*:*:*:*:*:*
References () https://syss.de - () https://syss.de - Not Applicable
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-008.txt - Third Party Advisory, Exploit

Information

Published : 2024-04-08 13:15

Updated : 2025-06-18 19:01


NVD link : CVE-2024-28066

Mitre link : CVE-2024-28066

CVE.ORG link : CVE-2024-28066


JSON object : View

Products Affected

mitel

  • openscape_cp210
  • openscape_cp410
  • 700d_dect
  • 6930w_firmware
  • openscape_cpx10_firmware
  • openscape_dect
  • 700d_dect_firmware
  • openscape_cpx10
  • 6970
  • openscape_cp410_firmware
  • 6970_firmware
  • openscape_dect_firmware
  • 6920w_firmware
  • openscape_cp710_firmware
  • 6915
  • 6905_firmware
  • openscape_cp110
  • 6940w_firmware
  • openscape_cp110_firmware
  • 6910
  • 6905
  • openscape_cp210_firmware
  • openscape_cp710
  • 6915_firmware
  • 6940w
  • 6930w
  • 6920w
  • 6910_firmware
CWE
CWE-259

Use of Hard-coded Password

CWE-1391

Use of Weak Credentials