Vulnerabilities > Mitel > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-05-29 CVE-2019-12165 Unspecified vulnerability in Mitel products
MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability.
network
low complexity
mitel
critical
9.8
2019-04-25 CVE-2018-18285 SQL Injection vulnerability in Mitel CMG Suite 8.4
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface.
network
low complexity
mitel CWE-89
critical
9.8
2019-04-25 CVE-2018-18286 SQL Injection vulnerability in Mitel CMG Suite 8.4
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the changepwd interface.
network
low complexity
mitel CWE-89
critical
9.8
2019-04-02 CVE-2018-19275 Insecure Default Initialization of Resource vulnerability in Mitel CMG Suite and Inattend
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.
network
low complexity
mitel CWE-1188
critical
9.8
2018-10-23 CVE-2018-15497 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mitel Mivoice 5330E Firmware 6.5.0.16
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.
network
low complexity
mitel CWE-119
critical
9.8
2018-03-14 CVE-2018-5782 Code Injection vulnerability in Mitel Connect Onsite and St14.2
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vsethost.php page.
network
low complexity
mitel CWE-94
critical
9.8
2018-03-14 CVE-2018-5781 Code Injection vulnerability in Mitel Connect Onsite and St14.2
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vendrecording.php page.
network
low complexity
mitel CWE-94
critical
9.8
2018-03-14 CVE-2018-5780 Code Injection vulnerability in Mitel Connect Onsite and St14.2
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vnewmeeting.php page.
network
low complexity
mitel CWE-94
critical
9.8
2018-03-14 CVE-2018-5779 Code Injection vulnerability in Mitel Connect Onsite and St14.2
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests.
network
low complexity
mitel CWE-94
critical
9.8