CVE detail
CVE-2019-18863 — CVE-2019-18863
Published 2020-03-02 · Modified 2026-06-17 · Vendor mitel · Product 6863i_firmware · Source nvd
MEDIUM
severity
CVSS-derived band
0.0051
EPSS probability
exploitation probability, 30d
41.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References