Are you at #39c3 and in need for some very good supported DECT (https://eventphone.de/doku/mitel_6xx_handsets) phones by the @eventphone system, like the #aastra / #mitel 620d/622d/622dv2?
A bunch of these handsets have accumulated in my possssion in various used conditions incl. belt clip, battery, charging stand, PSU.
Used market value ranging from 15€ to 100€.
It would be awesome if these will be put to good use by their new owners #hackerSeeksHW / #HWseeksHacker.
Monetary or hardware exchange possible, inspect, decide on a first come first served basis.
Send me a DM or reach out to me on DECT 7891.
Northern Telecom M9316 telephone
Mitel has released software updates to address vulnerabilities in MiVoice MX-ONE
Vulnerability: Improper access control
Impact:
- Attackers can bypass authentication and gain access to administrator accounts
- Affects versions 7.3 (7.3.0.0.50) to 7.8 SP1 (7.8.1.0.14)
Remediation:
- Update to versions 7.8 (MXO-15711_78SP0) and 7.8 SP1 (MXO-15711_78SP1)
Arctic Wolf a signalé une vulnérabilité critique de contournement d’authentification dans le Mitel MiVoice MX-ONE Provisioning Manager. Cette faille permet à des attaquants distants non authentifiés d’accéder sans autorisation aux systèmes vocaux et aux comptes utilisateurs ou administrateurs. Bien qu’aucune exploitation active n’ait été observée, la CISA a précédemment averti que des groupes de ransomware ciblaient les systèmes Mitel. Les organisations concernées sont invitées à mettre à jour immédiatement vers les versions corrigées ou à appliquer des solutions de contournement pour restreindre l’accès au service Provisioning Manager.
What I really hate is computer that get firmware updates only when you have a license.
Looking at https://www.mitel.com/ currently.
Have a used Mitel SIP phone with old old firmware and can not update the firmware as I can not find firmware files.
#mitel
#BSI WID-SEC-2025-1109: [NEU] [mittel] #Mitel #OpenScape #Xpressions: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Mitel OpenScape Xpressions ausnutzen, um Informationen offenzulegen.
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1109
#BSI WID-SEC-2025-0967: [NEU] [hoch] #Mitel #SIP #Phone: Mehrere Schwachstellen
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Mitel SIP Phone ausnutzen, um temporäre Dateien zu erzeugen oder beliebigen Programmcode auszuführen.
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-0967