I have 6 Mitel 5000 phone systems. I don't know much about them. I'm required to run quarterly vulnerability scans and all 6 have been flagged for the following item rated high. Does anyone know much about this, or have any official response from Mitel? Thanks so much.
Vulnerability: OpenSSL CCS Man in the Middle Security Bypass Vulnerability
Severity: High
Description: OpenSSL does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the 'CCS Injection' vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information by conducting a man-in-the-middle attack. This may lead to other attacks.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224