VYPR

Vendor CVEs

Mitel

All CVEs

152 total · sorted by risk
  • CVE-2021-32067MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP response due to insufficient output sanitization.

  • CVE-2021-27402MedAug 13, 2021
    risk 0.42cvss 6.5epss 0.01

    The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbitrary directory paths due to improper URL validation, aka Directory Traversal.

  • CVE-2020-9379MedFeb 25, 2020
    risk 0.42cvss 6.5epss 0.01

    The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful exploit could allow unauthorized access to user conversations.

  • CVE-2018-9102MedApr 25, 2018
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient…

  • CVE-2020-11798MedJun 10, 2020
    risk 0.41cvss 5.3epss 0.49

    A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A…

  • CVE-2003-20001MedApr 1, 2025
    risk 0.40cvss 5.6epss 0.02

    An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the login wait time and an external call comes in, the system incorrectly divulges information about the call and any SMDR records generated by the system. The…

  • CVE-2024-35283MedMay 29, 2024
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation.

  • CVE-2024-31966MedMay 2, 2024
    risk 0.40cvss 6.2epss 0.00

    A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct an argument injection attack due to…

  • CVE-2023-25598MedMay 24, 2023
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the home.php…

  • CVE-2021-27401MedAug 13, 2021
    risk 0.40cvss 6.1epss 0.01

    The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).

  • CVE-2020-27340MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.

  • CVE-2020-25611MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.

  • CVE-2020-25606MedDec 18, 2020
    risk 0.40cvss 6.1epss 0.01

    The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input validation, aka XSS.

  • CVE-2020-12679MedMay 7, 2020
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.

  • CVE-2019-19371MedMar 2, 2020
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the join meeting interface. A…

  • CVE-2019-19370MedMar 2, 2020
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.0.15 for Android could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the file…

  • CVE-2018-16226MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful…

  • CVE-2018-12901MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit…

  • CVE-2018-9104MedApr 25, 2018
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS)…

  • CVE-2018-9103MedApr 25, 2018
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS)…

  • CVE-2018-9101MedApr 25, 2018
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS)…

  • CVE-2024-55550LowKEVDec 10, 2024
    risk 0.39cvss 2.7epss 0.38

    Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to…

  • CVE-2023-25597MedApr 14, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit…

  • CVE-2020-13767MedAug 26, 2020
    risk 0.38cvss 5.9epss 0.01

    The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successful) could allow an attacker to gain access to sensitive…

  • CVE-2019-18863MedMar 2, 2020
    risk 0.38cvss 5.9epss 0.01

    A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the…

  • CVE-2019-19891MedJan 13, 2020
    risk 0.38cvss 5.9epss 0.00

    An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-in-the-middle attack. A successful exploit may allow the attacker to intercept sensitive information.

  • CVE-2024-35315MedOct 21, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit…

  • CVE-2023-39288MedAug 25, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A…

  • CVE-2023-39287MedAug 25, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A…

  • CVE-2024-35284MedMay 29, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation.

  • CVE-2021-32070MedAug 13, 2021
    risk 0.35cvss 5.4epss 0.01

    The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users.

  • CVE-2020-25610MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.01

    The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.

  • CVE-2020-25609MedDec 18, 2020
    risk 0.35cvss 5.4epss 0.01

    The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.

  • CVE-2020-24595MedSep 25, 2020
    risk 0.35cvss 5.3epss 0.01

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.

  • CVE-2020-24592MedSep 25, 2020
    risk 0.35cvss 5.3epss 0.01

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.

  • CVE-2018-18819MedNov 12, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP1…

  • CVE-2017-16250MedMar 13, 2018
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associated user names.

  • CVE-2023-39291MedAug 25, 2023
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker…

  • CVE-2023-39290MedAug 25, 2023
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an…

  • CVE-2021-37586MedAug 13, 2021
    risk 0.32cvss 4.9epss 0.01

    The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Administrator rights) to replay a previously recorded conversation of another tenant due to insufficient validation.

  • CVE-2020-25612MedDec 18, 2020
    risk 0.32cvss 4.9epss 0.01

    The NuPoint Messenger of Mitel MiCollab before 9.2 could allow an attacker with escalated privilege to access user files due to insufficient access control. Successful exploit could potentially allow an attacker to gain access to sensitive information.

  • CVE-2024-30160MedOct 21, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful…

  • CVE-2024-30159MedOct 21, 2024
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful exploit…

  • CVE-2021-32069MedAug 13, 2021
    risk 0.31cvss 4.8epss 0.01

    The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation. A successful exploit could allow an attacker to view and modify data.

  • CVE-2023-39286MedSep 14, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an…

  • CVE-2023-39285MedSep 14, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an…

  • CVE-2024-31965MedMay 2, 2024
    risk 0.27cvss 4.2epss 0.00

    A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct a path traversal attack due to…

  • CVE-2021-32068LowAug 13, 2021
    risk 0.24cvss 3.7epss 0.01

    The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack by sending multiple session renegotiation requests, due to insufficient TLS session controls. A successful exploit could allow an attacker to…

  • CVE-2020-24693LowDec 18, 2020
    risk 0.21cvss 3.3epss 0.00

    The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization.

  • CVE-2008-6797May 7, 2009
    risk 0.00cvss —epss 0.02

    The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obtain sensitive information by sniffing the network.