Vulnerabilities > CVE-2020-24595 - Incorrect Authorization vulnerability in Mitel Micloud Management Portal 5.3/6.0/6.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
mitel
CWE-863

Summary

Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.

Common Weakness Enumeration (CWE)