Vulnerability index

Browse CVEs

120 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mivoice Connect MEDIUM 5.5
CVE-2023-39287

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with ele…

Fix: after 22.24.5800.0
Fix from $1,600 2023-08-25
Mivoice Connect MEDIUM 5.5
CVE-2023-39288

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with ele…

Fix: after 9.6.2304.102
Fix from $1,600 2023-08-25
Mivoice Office 400 CRITICAL 9.8
CVE-2023-39293

A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor t…

Fix: after 7.0.9281
Fix from $2,300 2023-08-14
Mivoice Office 400 CRITICAL 9.8
CVE-2023-39292

A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to ac…

Fix: after 7.0.9281
Fix from $2,300 2023-08-14
Mivoice Connect CRITICAL 9.8
CVE-2023-32748

The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network…

Fix: after 22.24.1500.0
Fix from $2,300 2023-08-14
Mivoice Connect CRITICAL 9.8
CVE-2023-31458

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated at…

Fix: after 22.24.1500.0
Fix from $2,300 2023-05-24
Mivoice Connect HIGH 7.4
CVE-2023-25599

A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2, 22.24.1500.0 could allow an unauthenticated attacker to cond…

Fix: after 22.24.1500.0
Fix from $1,950 2023-05-24
Mivoice Connect HIGH 8.8
CVE-2023-31459

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated at…

Fix: after 9.6.2208.101
Fix from $1,950 2023-05-24
Mivoice Connect HIGH 7.2
CVE-2023-31460

A vulnerability in the Connect Mobility Router component of MiVoice Connect versions 9.6.2208.101 and earlier could allow an authenticated attacker w…

Fix: after 9.6.2208.101
Fix from $1,950 2023-05-24
Mivoice Connect CRITICAL 9.8
CVE-2023-31457

A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthentic…

Fix: after 22.24.1500.0
Fix from $2,300 2023-05-24
Mivoice Connect MEDIUM 6.1
CVE-2023-25598

A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an …

Fix: after 22.24.1500.0
Fix from $1,600 2023-05-24
Micollab MEDIUM 5.9
CVE-2023-25597

A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file…

Fix: 9.7+
Fix from $1,600 2023-04-14
Micontact Center Business HIGH 7.5
CVE-2023-22854

The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary …

Fix: 9.4.2.0+
Fix from $1,950 2023-02-13
Micollab CRITICAL 9.8
CVE-2022-41326

The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper…

Fix: after 9.6.0.105
Fix from $2,300 2022-11-22
Mivoice Connect MEDIUM 6.8
CVE-2022-41223 KEVEPSS 11%

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection atta…

Fix: after 22.22.6100.0
Fix from $1,600 2022-11-22
Mivoice Connect MEDIUM 6.8
CVE-2022-40765 KEVEPSS 10%

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with interna…

Fix: after 22.22.6100.0
Fix from $1,600 2022-11-22
Micollab CRITICAL 9.8
CVE-2022-36452

A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious fil…

Fix: 9.6+
Fix from $2,300 2022-10-25
Micollab HIGH 8.8
CVE-2022-36451

A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server…

Fix: after 9.5.0.101
Fix from $1,950 2022-10-25
Micollab HIGH 8.8
CVE-2022-36453

A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile pa…

Fix: after 9.5.0.101
Fix from $1,950 2022-10-25
Micollab MEDIUM 6.5
CVE-2022-36454

A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile paramete…

Fix: after 9.5.0.101
Fix from $1,600 2022-10-25
Mivoice Business CRITICAL 9.8
CVE-2022-31784

A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unaut…

Fix: after 9.3.0.27
Fix from $2,300 2022-06-17
Minet Firmware MEDIUM 6.8
CVE-2022-29854

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker wi…

Fix: after 1.8.0.12
Fix from $1,600 2022-05-13
6873i Sip Firmware MEDIUM 6.8
CVE-2022-29855

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Seri…

Fix: 5.1.0.8017 / 6.1.0.171+
Fix from $1,600 2022-05-11
Mivoice Connect CRITICAL 9.8
CVE-2022-29499 KEVEPSS 55%

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Serv…

Fix: after 22.20.2300.0
Fix from $2,300 2022-04-26
Micollab CRITICAL 9.8
CVE-2022-26143 KEVEPSS 87%

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain s…

Fix: 9.4+
Fix from $2,300 2022-03-10
Micontact Center Business CRITICAL 9.1
CVE-2021-3352

The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticat…

Fix: after 9.3.1.0
Fix from $2,300 2021-08-13
Micollab CRITICAL 9.8
CVE-2021-32071

The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control. A …

Fix: 9.3+
Fix from $2,300 2021-08-13
Micollab MEDIUM 6.5
CVE-2021-27402

The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify) user data by injecting arbi…

Fix: 9.2+
Fix from $1,600 2021-08-13
Micollab MEDIUM 6.5
CVE-2021-32067

The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP respo…

Fix: 9.3+
Fix from $1,600 2021-08-13
Micollab MEDIUM 6.5
CVE-2021-32072

The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code information (disclosing sensitive appli…

Fix: 9.3+
Fix from $1,600 2021-08-13