Vulnerabilities > Mitel > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-13 | CVE-2023-22854 | Unspecified vulnerability in Mitel Micontact Center Business The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. | 7.5 |
2022-10-25 | CVE-2022-36451 | Server-Side Request Forgery (SSRF) vulnerability in Mitel Micollab A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server-Side Request Forgery (SSRF) attack due to insufficient restriction of URL parameters. | 8.8 |
2022-10-25 | CVE-2022-36453 | Unspecified vulnerability in Mitel Micollab A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. | 8.8 |
2021-01-29 | CVE-2021-3176 | Improper Input Validation vulnerability in Mitel Businesscti Enterprise The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could allow an attacker to gain access to user information by sending certain code, due to improper input validation of http links. | 8.0 |
2020-12-18 | CVE-2020-27640 | Unspecified vulnerability in Mitel Mivoice 6930 Firmware and Mivoice 6940 Firmware The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. low complexity mitel | 8.1 |
2020-12-18 | CVE-2020-27639 | Unspecified vulnerability in Mitel products The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within Bluetooth range to pair a rogue Bluetooth device when a phone handset loses connection, due to an improper pairing mechanism. low complexity mitel | 8.1 |
2020-12-18 | CVE-2020-27154 | Improper Input Validation vulnerability in Mitel Businesscti Enterprise 6.4.10/7.0.0/7.0.2 The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. | 8.8 |
2020-12-18 | CVE-2020-25608 | SQL Injection vulnerability in Mitel Micollab The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection. | 7.2 |
2020-09-25 | CVE-2020-24692 | Improper Input Validation vulnerability in Mitel Micontact Center Business The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. | 7.1 |
2020-09-25 | CVE-2020-24593 | SQL Injection vulnerability in Mitel Micloud Management Portal 5.3/6.0/6.1 Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation. | 7.2 |