Vulnerabilities > Mitel > Micollab > 9.1.2

DATE CVE VULNERABILITY TITLE RISK
2021-08-13 CVE-2021-32069 Improper Certificate Validation vulnerability in Mitel Micollab
The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation.
network
mitel CWE-295
5.8
2021-08-13 CVE-2021-32070 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitel Micollab
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response.
network
mitel CWE-1021
5.8
2021-08-13 CVE-2021-32071 Unspecified vulnerability in Mitel Micollab
The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control.
network
low complexity
mitel
7.5
2021-08-13 CVE-2021-32072 Improper Encoding or Escaping of Output vulnerability in Mitel Micollab
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code information (disclosing sensitive application data) due to insufficient output sanitization.
network
low complexity
mitel CWE-116
4.0
2021-01-29 CVE-2020-35547 Incorrect Authorization vulnerability in Mitel Micollab
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
network
low complexity
mitel CWE-863
6.4
2020-12-18 CVE-2020-27340 Open Redirect vulnerability in Mitel Micollab
The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.
network
mitel CWE-601
5.8
2020-12-18 CVE-2020-25612 Incorrect Authorization vulnerability in Mitel Micollab
The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control.
network
low complexity
mitel CWE-863
4.0
2020-12-18 CVE-2020-25611 Cross-site Scripting vulnerability in Mitel Micollab
The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS.
network
mitel CWE-79
4.3
2020-12-18 CVE-2020-25610 Incorrect Authorization vulnerability in Mitel Micollab
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.
network
low complexity
mitel CWE-863
5.0
2020-12-18 CVE-2020-25609 Cross-site Scripting vulnerability in Mitel Micollab
The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS.
network
mitel CWE-79
3.5