Vulnerabilities > Mitel

DATE CVE VULNERABILITY TITLE RISK
2021-01-29 CVE-2021-3176 Improper Input Validation vulnerability in Mitel Businesscti Enterprise
The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could allow an attacker to gain access to user information by sending certain code, due to improper input validation of http links.
network
low complexity
mitel CWE-20
8.0
2021-01-29 CVE-2020-35547 Unspecified vulnerability in Mitel Micollab
A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.
network
low complexity
mitel
critical
9.1
2020-12-18 CVE-2020-27640 Unspecified vulnerability in Mitel Mivoice 6930 Firmware and Mivoice 6940 Firmware
The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism.
low complexity
mitel
8.1
2020-12-18 CVE-2020-27639 Unspecified vulnerability in Mitel products
The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism.
low complexity
mitel
8.1
2020-12-18 CVE-2020-27340 Unspecified vulnerability in Mitel Micollab
The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.
network
low complexity
mitel
6.1
2020-12-18 CVE-2020-27154 Improper Input Validation vulnerability in Mitel Businesscti Enterprise 6.4.10/7.0.0/7.0.2
The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation.
network
low complexity
mitel CWE-20
8.8
2020-12-18 CVE-2020-25612 Unspecified vulnerability in Mitel Micollab
The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control.
network
low complexity
mitel
4.9
2020-12-18 CVE-2020-25611 Improper Input Validation vulnerability in Mitel Micollab
The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS.
network
low complexity
mitel CWE-20
6.1
2020-12-18 CVE-2020-25610 Unspecified vulnerability in Mitel Micollab
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.
network
low complexity
mitel
5.3
2020-12-18 CVE-2020-25609 Cross-site Scripting vulnerability in Mitel Micollab
The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS.
network
low complexity
mitel CWE-79
5.4