Vulnerabilities > Mitel
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-13 | CVE-2021-37586 | Improper Input Validation vulnerability in Mitel Interaction Recording 6.6 The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Administrator rights) to replay a previously recorded conversation of another tenant due to insufficient validation. | 4.9 |
2021-08-13 | CVE-2021-3352 | Unspecified vulnerability in Mitel Micontact Center Business The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without authorization due to improper handling of tokens. | 9.1 |
2021-03-29 | CVE-2021-26714 | Unspecified vulnerability in Mitel Micontact Center Enterprise 9.3 The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. | 9.8 |
2021-01-29 | CVE-2021-3176 | Improper Input Validation vulnerability in Mitel Businesscti Enterprise The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could allow an attacker to gain access to user information by sending certain code, due to improper input validation of http links. | 8.0 |
2021-01-29 | CVE-2020-35547 | Unspecified vulnerability in Mitel Micollab A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data. | 9.1 |
2020-12-18 | CVE-2020-27640 | Unspecified vulnerability in Mitel Mivoice 6930 Firmware and Mivoice 6940 Firmware The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. low complexity mitel | 8.1 |
2020-12-18 | CVE-2020-27639 | Unspecified vulnerability in Mitel products The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. low complexity mitel | 8.1 |
2020-12-18 | CVE-2020-27340 | Unspecified vulnerability in Mitel Micollab The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control. | 6.1 |
2020-12-18 | CVE-2020-27154 | Improper Input Validation vulnerability in Mitel Businesscti Enterprise 6.4.10/7.0.0/7.0.2 The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. | 8.8 |
2020-12-18 | CVE-2020-25612 | Unspecified vulnerability in Mitel Micollab The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. | 4.9 |