Mitel

Mivoice Connect

25 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 24.05.2023 20:15:10
  • Last modified 31.01.2025 14:15:32

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initi...

  • EPSS 0.32%
  • Published 24.05.2023 20:15:09
  • Last modified 17.01.2025 16:15:29

A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient...

  • EPSS 0.52%
  • Published 24.05.2023 20:15:09
  • Last modified 31.01.2025 14:15:32

A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access contro...

Warning
  • EPSS 3.32%
  • Published 22.11.2022 01:15:32
  • Last modified 07.02.2025 14:53:04

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

Warning
  • EPSS 2.95%
  • Published 22.11.2022 01:15:31
  • Last modified 04.02.2025 14:52:50

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parame...

Warning
  • EPSS 89.83%
  • Published 26.04.2022 02:15:37
  • Last modified 14.03.2025 20:00:30

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

  • EPSS 1.34%
  • Published 26.08.2020 19:15:14
  • Last modified 21.11.2024 04:59:44

A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A successful exploit could allo...

  • EPSS 0.22%
  • Published 07.05.2020 17:15:11
  • Last modified 21.11.2024 05:00:03

A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.

  • EPSS 0.11%
  • Published 17.04.2020 13:15:12
  • Last modified 21.11.2024 04:55:10

A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compromised user ...

  • EPSS 1.68%
  • Published 17.04.2020 13:15:12
  • Last modified 21.11.2024 04:54:58

A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could a...