VYPR

Mitel Nupoint Messenger

by Mitel

CVEs (7)

  • CVE-2024-35286CriOct 21, 2024
    risk 0.69cvss 9.8epss 0.65

    A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and…

  • CVE-2024-35285CriOct 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.

  • CVE-2020-35547CriJan 29, 2021
    risk 0.59cvss 9.1epss 0.01

    A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) to user data.

  • CVE-2024-35287MedOct 21, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary…

  • CVE-2020-25609MedDec 18, 2020
    risk 0.35cvss 5.4epss 0.01

    The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.

  • CVE-2020-25612MedDec 18, 2020
    risk 0.32cvss 4.9epss 0.01

    The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. Successful exploit could potentially allow an attacker to gain access to sensitive information.

  • CVE-2008-6797May 7, 2009
    risk 0.00cvss epss 0.02

    The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obtain sensitive information by sniffing the network.