Vulnerability index

Browse CVEs

120 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Micollab MEDIUM 6.1
CVE-2021-27401

The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrar…

Fix: 9.2+
Fix from $1,600 2021-08-13
Micollab MEDIUM 5.4
CVE-2021-32070

The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header…

Fix: 9.3+
Fix from $1,600 2021-08-13
Micontact Center Enterprise CRITICAL 9.8
CVE-2021-26714

The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due t…

Fix: 9.4+
Fix from $2,300 2021-03-29
Micollab CRITICAL 9.1
CVE-2020-35547

A library index page in NuPoint Messenger in Mitel MiCollab before 9.2 FP1 could allow an unauthenticated attacker to gain access (view and modify) t…

Fix: after 9.2
Fix from $2,300 2021-01-29
Businesscti Enterprise HIGH 8.0
CVE-2021-3176

The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could allow an attacker to gain acc…

Fix: 6.4.15 / 7.1.2+
Fix from $1,950 2021-01-29
Businesscti Enterprise HIGH 8.8
CVE-2020-27154

The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access …

Fix: 6.4.11 / 7.0.3+
Fix from $1,950 2020-12-18
6873i Sip Firmware HIGH 8.1
CVE-2020-27639

The Bluetooth handset of Mitel MiVoice 6873i, 6930, and 6940 SIP phones with firmware before 5.1.0.SP6 could allow an unauthenticated attacker within…

Fix: 5.1.0+
Fix from $1,950 2020-12-18
Mivoice 6940 Firmware HIGH 8.1
CVE-2020-27640

The Bluetooth handset of Mitel MiVoice 6940 and 6930 MiNet phones with firmware before 1.5.3 could allow an unauthenticated attacker within Bluetooth…

Fix: 1.5.3+
Fix from $1,950 2020-12-18
Micollab HIGH 7.2
CVE-2020-25608

The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.

Fix: 9.2+
Fix from $1,950 2020-12-18
Micollab MEDIUM 6.1
CVE-2020-25606

The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input val…

Fix: 9.2+
Fix from $1,600 2020-12-18
Micollab MEDIUM 6.1
CVE-2020-25611

The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to imprope…

Fix: 9.2+
Fix from $1,600 2020-12-18
Micollab MEDIUM 6.1
CVE-2020-27340

The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious scri…

Fix: 9.2+
Fix from $1,600 2020-12-18
Micollab MEDIUM 5.4
CVE-2020-25609

The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient inpu…

Fix: 9.2+
Fix from $1,600 2020-12-18
Micollab MEDIUM 5.3
CVE-2020-25610

The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conf…

Fix: 9.2+
Fix from $1,600 2020-12-18
Shoretel Firmware MEDIUM 6.1
CVE-2020-28351EPSS 16%

The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting…

No fix yet
Fix from $1,600 2020-11-09
Micloud Management Portal CRITICAL 9.6
CVE-2020-24594

Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validat…

Fix: after 6.0
Fix from $2,300 2020-09-25
Micloud Management Portal HIGH 7.2
CVE-2020-24593

Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to imp…

Fix: after 6.0
Fix from $1,950 2020-09-25
Micontact Center Business HIGH 7.1
CVE-2020-24692

The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input va…

Fix: 9.3.0.0+
Fix from $1,950 2020-09-25
Micloud Management Portal MEDIUM 5.3
CVE-2020-24592

Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient …

Fix: after 6.0
Fix from $1,600 2020-09-25
Micloud Management Portal MEDIUM 5.3
CVE-2020-24595

Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insuff…

Fix: after 6.0
Fix from $1,600 2020-09-25
Mivoice Connect Client HIGH 8.8
CVE-2020-12456

A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the …

Fix: 214.100.1223.0+
Fix from $1,950 2020-08-26
Micollab Audio\, Web \& Video Conferencing HIGH 7.5
CVE-2020-11797

An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.…

Fix: 8.1.2.4 / 9.1.3+
Fix from $1,950 2020-08-26
Micollab HIGH 8.1
CVE-2020-13863

The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to …

Fix: 9.1.3+
Fix from $1,950 2020-08-26
6863 Firmware HIGH 7.5
CVE-2020-13617

The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expos…

Fix: after 5.0
Fix from $1,950 2020-08-26
Micollab MEDIUM 5.9
CVE-2020-13767

The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient acc…

Fix: 9.1.332+
Fix from $1,600 2020-08-26
Micollab Audio\, Web \& Video Conferencing MEDIUM 5.3
CVE-2020-11798EPSS 49%

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker…

Fix: 8.1.2.4 / 9.1.3+
Fix from $1,600 2020-06-10
Mivoice Connect MEDIUM 6.1
CVE-2020-12679

A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 al…

Fix: 21.90.9743.0+
Fix from $1,600 2020-05-07
Mivoice Connect CRITICAL 9.8
CVE-2020-10211

A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to exe…

Fix: 22.11.4900.0+
Fix from $2,300 2020-04-17
Mivoice Connect Client CRITICAL 9.8
CVE-2020-10377

A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user …

Fix: after 214.100.1213.0
Fix from $2,300 2020-04-17
Micollab Audio\, Web \& Video Conferencing CRITICAL 9.8
CVE-2019-19607

A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to ins…

Fix: after 8.1.1.11
Fix from $2,300 2020-03-02