CVE-2024-41710

Published Aug 12, 2024

Last updated 7 days ago

Overview

Description
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Mitel SIP Phones Argument Injection Vulnerability
Exploit added on
Feb 12, 2025
Exploit action due
Mar 5, 2025
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-88
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-88

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2024-41710

    @transilienceai

    14 Feb 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 🚨 CVE Alert: Mitel SIP Phones Argument Injection Vulnerability Exploited In The Wild🚨 Vulnerability Details: CVE-2024-41710 (CVSS 6.8/10) Mitel SIP Phones Argument Injection Vulnerability Impact: A Successful exploit may allow an attacker to execute arbitrary commands within…

    @CyberxtronTech

    13 Feb 2025

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2024-41710 #Mitel SIP Phones Argument Injection Vulnerability https://t.co/Ia3RNbs63A

    @ScyScan

    12 Feb 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Actively exploited CVE : CVE-2024-41710

    @transilienceai

    10 Feb 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Actively exploited CVE : CVE-2024-41710

    @transilienceai

    9 Feb 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Actively exploited CVE : CVE-2024-41710

    @transilienceai

    9 Feb 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Actively exploited CVE : CVE-2024-41710

    @transilienceai

    7 Feb 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. Aquabotv3 malware targets Mitel SIP phones with critical vulnerability CVE-2024-41710. Stay informed here: https://t.co/qhhq1wRuiq #Cybersecurity

    @threatlight

    5 Feb 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks https://t.co/VeDGdeqIOL via @TheHackersNews

    @newsoft53759560

    3 Feb 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Akamai SIRT reports Aquabotv3, a new variant of the Aquabot malware, exploiting CVE-2024-41710, a SQL injection flaw in Mitel SIP phones. Evolving from its 2023 version, Aquabotv3 introduces report_kill(), notifying the C2 server when terminated. Its goal is likely DDoS attacks.

    @Cyber_Sec_Raj

    3 Feb 2025

    179 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. The new Aquabot Botnet is taking advantage of CVE-2024-41710 on Mitel phones for DDOS attacks https://t.co/VQZgBTENt2

    @techonanet

    2 Feb 2025

    135 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks https://t.co/JYvUy2wDEj #Mitel https://t.co/wNAdjgCeTY

    @digiSOLcomau

    2 Feb 2025

    134 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Akamai has issued a warning about active attacks from a new Mirai variant, Aquabotv3, which exploits a vulnerability in Mitel internet-connected phones (CVE-2024-41710). #InfoSec #CyberSecurity https://t.co/aeMSxziJtd

    @SaifuddinAmri__

    1 Feb 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks https://t.co/3Fid5Q46aj via @TheHackersNews

    @DCICyberSecNews

    1 Feb 2025

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. #exploit 1. CVE-2024-12847: Exposing an Old Netgear Vulnerability Still Active in 2025 - https://t.co/qRmuxKaxqT 2. RCE in Lightning AI-development platform - https://t.co/dyiZO28pin 3. CVE-2024-41710: Mitel phones Argument Injection - https://t.co/Qv6bpjmKWk 3.… https://t.co

    @ksg93rd

    31 Jan 2025

    189 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. csirt_it: #Botnet: nuova variante di #Aquabot effettua tentativi di sfruttamento della CVE-2024-41710 relativa a prodotti #Mitel Criticità: 🟠 Tipologia: 🔸 Remote Code Execution 🔗 https://t.co/fxGUqdqvTE ⚠ mantenere i dispositivi aggiornati 👉 M… https://t.co/49zjxNNvjF

    @Vulcanux_

    31 Jan 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks Read More : https://t.co/bQqkzWroor https://t.co/uTPTlLd2iH

    @techpio_team

    31 Jan 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. A new variant of the Mirai-based botnet malware Aquabot has been observed actively exploiting CVE-2024-41710, a command injection vulnerability in Mitel SIP phones. https://t.co/gbir8UlJmQ #rhymtech #thinkcyberthinkrhym #rhymcyberupdates

    @Rhym_Tech

    31 Jan 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Una nueva variante del botnet Aquabot está explotando la vulnerabilidad CVE-2024-41710 en teléfonos Mitel para lanzar ataques de denegación de servicio distribuido (DDoS). Esta vulnerabilidad afecta a los modelos de teléfonos SIP de las series 6800, 6900 y 6900w de Mitel.… https

    @citarafy

    30 Jan 2025

    34 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  20. A new Mirai botnet variant, Aquabotv3, is exploiting a vulnerability (CVE-2024-41710) in Mitel SIP phones for DDoS attacks. This version shows significant advancements in botnet control and propagation, posing a serious threat to organizations and individuals. Aquabotv3 sets… ht

    @cytexsmb

    30 Jan 2025

    81 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  21. 🗞️ New Aquabotv3 Botnet Malware Targets Mitel Command Injection Vulnerability The recently identified Aquabotv3 botnet is exploiting a command injection flaw in Mitel SIP phones (CVE-2024-41710) to expand its network for DDoS attacks. This Mirai-based threat introduces novel… h

    @gossy_84

    30 Jan 2025

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. New #Aquabot #Botnet Exploits #CVE-2024-41710 in Mitel Phones for #DDoS #Attacks https://t.co/6wq6cKuNyv

    @ScyScan

    30 Jan 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks #CISO https://t.co/bmRyq1cYcj https://t.co/0SVllZczB2

    @compuchris

    30 Jan 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. A new variant of the Mirai-based botnet #malware Aquabot has been observed actively exploiting CVE-2024-41710, a command injection #vulnerability in Mitel SIP phones☝️☠️ https://t.co/HnbSHhuwKL https://t.co/D6mHWwaQw9

    @manuelbissey

    30 Jan 2025

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. Aquabot Exploits Mitel Flaw CVE-2024-41710 #aquabot #CVE-2024-41710 #Mitel https://t.co/8ClporhlHi

    @pravin_karthik

    30 Jan 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks https://t.co/7fHXWkJSq1 https://t.co/HxPBi9nwou

    @TonyBeeTweets

    30 Jan 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks https://t.co/R5Gy616PDF https://t.co/LXhkt8utzH

    @talentxfactor

    30 Jan 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks. A Mirai botnet variant dubbed Aquabot has been observed actively attempting to exploit a medium-severity security flaw impacting Mitel... https://t.co/JkWr5Tanhr #InceptusSecure #UnderOurProtection

    @Inceptus3

    30 Jan 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks https://t.co/VeDGdeqIOL via @TheHackersNews

    @newsoft53759560

    30 Jan 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. A new variant of the Mirai botnet, Aquabot, exploits the CVE-2024-41710 flaw in Mitel phones to launch DDoS attacks. Multiple models are affected, highlighting ongoing security risks. 🔒📞 #MitelPhones #DDoSThreat #USA link: https://t.co/JIsskM1la0 https://t.co/CEURxeFJeY

    @TweetThreatNews

    30 Jan 2025

    95 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  31. The Hacker News - New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks https://t.co/s0ZQmtCJKi

    @buzz_sec

    30 Jan 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. New Aquabotv3 botnet malware variant actively exploits CVE-2024-41710 command injection flaw in Mitel SIP phones. Stay vigilant! #Cybersecurity #InfoSec #Malware https://t.co/5BQ2cNSbY9

    @fishpassenger

    30 Jan 2025

    148 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    5 Replies

    0 Quotes

  33. Hay una nueva variante del malware botnet basado en Mirai Aquabot (CVE-2024-41710), una vulnerabilidad que afecta a los teléfonos SIP Mitel de las series 6800, 6900 y 6900w, normalmente utilizados en oficinas, empresas, gobiernos, hospitales, educación, hoteles y financieras. 🧉

    @MarquisioX

    30 Jan 2025

    43 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. A new variant of the Mirai-based Aquabot malware is reportedly exploiting the Mitel command injection flaw, CVE-2024-41710, targeting SIP phones. #CyberSecurity #Malware https://t.co/xlzgbnAJW7

    @Cyber_O51NT

    30 Jan 2025

    235 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 🚨 New Aquabotv3 botnet exploits a Mitel command injection flaw (CVE-2024-41710), affecting SIP phones. Unusual behavior detected with kill reports to its server. Fixes are available! 📞⚠️ #Mitel #Malware #Botnet link: https://t.co/xdTDHzvPEW https://t.co/rGJizPSNaa

    @TweetThreatNews

    30 Jan 2025

    136 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Aquabot botnet, powered by Mirai, targets vulnerable Mitel SIP phones via the CVE-2024-41710 vulnerability, posing a risk for DDoS attacks. Mitel has released critical firmware updates. 🔒📞 #Mitel #DDoSThreat #USA link: https://t.co/jFA4dQHYbN https://t.co/niiG9K5YrE

    @TweetThreatNews

    29 Jan 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨Threat Campaign Alert - Aquabotv3: New Mirai-Based Botnet Exploits Mitel SIP Phones (CVE-2024-41710) for DDoS Attacks🚨 Summary: Researchers have discovered Aquabotv3, a new Mirai-based botnet variant, actively exploiting CVE-2024-41710 in Mitel SIP phones. This malware… https

    @CyberxtronTech

    29 Jan 2025

    115 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations