Vulnerabilities > Mitel > Mivoice Connect > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-25 CVE-2023-39289 Unspecified vulnerability in Mitel Mivoice Connect
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration.
network
low complexity
mitel
7.5
2023-05-24 CVE-2023-25599 Cross-site Scripting vulnerability in Mitel Mivoice Connect 19.1/19.3
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the test_presenter.php page.
network
low complexity
mitel CWE-79
7.4
2023-05-24 CVE-2023-31459 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Mitel Mivoice Connect
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change.
low complexity
mitel CWE-640
8.8
2023-05-24 CVE-2023-31460 Command Injection vulnerability in Mitel Mivoice Connect
A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters.
network
low complexity
mitel CWE-77
7.2
2020-04-17 CVE-2020-10211 Improper Input Validation vulnerability in Mitel Mivoice Connect and Mivoice Connect Client
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters.
network
low complexity
mitel CWE-20
7.5