CVE-2024-28066
HIGHDescription
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
Is your site exposed to CVE-2024-28066?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mitel | 6940w_firmware |
| mitel | 6940w |
| mitel | 6930w_firmware |
| mitel | 6930w |
| mitel | 6920w_firmware |
| mitel | 6920w |
| mitel | 6970_firmware |
| mitel | 6970 |
| mitel | 6915_firmware |
| mitel | 6915 |
| mitel | 6910_firmware |
| mitel | 6910 |
| mitel | 6905_firmware |
| mitel | 6905 |
| mitel | openscape_cp710_firmware |
| mitel | openscape_cp710 |
| mitel | openscape_cp410_firmware |
| mitel | openscape_cp410 |
| mitel | openscape_cp210_firmware |
| mitel | openscape_cp210 |
| mitel | openscape_cp110_firmware |
| mitel | openscape_cp110 |
| mitel | openscape_cpx10_firmware |
| mitel | openscape_cpx10 |
| mitel | openscape_dect_firmware |
| mitel | openscape_dect |
| mitel | 700d_dect_firmware |
| mitel | 700d_dect |
References
Frequently Asked Questions
What is CVE-2024-28066? +
How severe is CVE-2024-28066? +
What products are affected by CVE-2024-28066? +
How do I check if I'm vulnerable to CVE-2024-28066? +
Related Vulnerabilities
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform …
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized …
A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond …
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password …
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services …
Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the …