10

CVE-2018-19275

The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitel ≫ Cmg Suite Version < 8.4
Mitel ≫ Cmg Suite Version 8.4 Update -
Mitel ≫ Cmg Suite Version 8.4 Update sp2
Mitel ≫ Inattend Version < 2.5
Mitel ≫ Inattend Version 2.5 Update -
Mitel ≫ Inattend Version 2.5 Update sp1
Mitel ≫ Inattend Version 2.5 Update sp2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.61% 0.905
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

https://www.mitel.com/-/media/mitel/pdf/security-advisories/security-bulletin-190002001-v10.pdf
Vendor Advisory
https://www.mitel.com/en-gb/support/security-advisories/mitel-product-security-advisory-19-0002
Vendor Advisory