CVE-2018-5779
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedA vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests. Successful exploit could allow an attacker to execute arbitrary code within the context of the application.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceA critical unauthenticated remote code execution vulnerability in Mitel Connect ONSITE (R1711-PREM and earlier) and Mitel ST 14.2 (GA28 and earlier) conferencing component allows attackers to write malicious PHP scripts to newly generated files and execute them, leading to arbitrary code execution within the application context.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data<= r1711-prem<= ga28CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify installed Mitel product and versionLocate the Mitel Connect application or service on the system. Check the application version through the admin interface, installation directory, or service information. For Mitel Connect ONSITE, look for version r1711-prem or earlier. For Mitel ST 14.2, look for version ga28 or earlier.Affected if The installed version is Mitel Connect Onsite r1711-prem or earlier, or Mitel ST 14.2 ga28 or earlier.
-
Verify the conferencing component is enabledAccess the Mitel admin interface and check the status of the conferencing component. This may be listed as 'conference', 'conferencing', or a similar feature within the application settings or service configuration.Affected if The conferencing component is installed and enabled in the Mitel configuration.
-
Check for unusual new PHP files in the application directoryInspect the web root or application data directories for newly created .php files that were not intentionally deployed. Look in the web-accessible directories where the conferencing component stores its files.Affected if Unexpected PHP files exist in the conferencing or web directories that were not created by administrators.
-
Review application logs for unauthorized conferencing activityExamine Mitel Connect or Mitel ST application logs for entries indicating unauthenticated file creation or PHP script execution requests, particularly those originating from external IP addresses.Affected if Logs show unauthenticated requests to create files or execute PHP scripts in the conferencing module.
A user is affected if they have Mitel Connect Onsite r1711-prem or earlier, or Mitel ST 14.2 ga28 or earlier, with the conferencing component enabled and exposed.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scopedUpgrade to patched versions of Mitel Connect ONSITE and Mitel ST beyond the affected releases. If immediate patching is not possible, disable or restrict access to the conferencing component and implement network segmentation.
Mitel Connect ONSITE version newer than R1711-PREM, or Mitel ST 14.2 version newer than GA28 (contact Mitel for specific patched release)
- 1. Identify the current Mitel Connect ONSITE or ST 14.2 version currently installed
- 2. Contact Mitel support or refer to Mitel's official security advisory to obtain the patched version
- 3. Schedule a maintenance window for the upgrade
- 4. Backup the current system configuration and any critical data
- 5. Apply the upgrade to a version newer than R1711-PREM for Connect ONSITE or newer than GA28 for ST 14.2
- 6. Verify the conferencing component is functioning correctly after upgrade
- 7. Monitor system logs for any unusual activity
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation4.0 h
- Implementation6.0 h
- Testing3.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $4,304.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2018-5779 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2018-5779 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data