Mitel

Mivoice Connect

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 24.05.2023 20:15:10
  • Zuletzt bearbeitet 31.01.2025 14:15:32

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initi...

  • EPSS 0.32%
  • Veröffentlicht 24.05.2023 20:15:09
  • Zuletzt bearbeitet 17.01.2025 16:15:29

A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient...

  • EPSS 0.52%
  • Veröffentlicht 24.05.2023 20:15:09
  • Zuletzt bearbeitet 31.01.2025 14:15:32

A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access contro...

Warnung
  • EPSS 3.32%
  • Veröffentlicht 22.11.2022 01:15:32
  • Zuletzt bearbeitet 07.02.2025 14:53:04

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

Warnung
  • EPSS 2.95%
  • Veröffentlicht 22.11.2022 01:15:31
  • Zuletzt bearbeitet 04.02.2025 14:52:50

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parame...

Warnung
  • EPSS 89.83%
  • Veröffentlicht 26.04.2022 02:15:37
  • Zuletzt bearbeitet 14.03.2025 20:00:30

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

  • EPSS 1.34%
  • Veröffentlicht 26.08.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 04:59:44

A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A successful exploit could allo...

  • EPSS 0.22%
  • Veröffentlicht 07.05.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:00:03

A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.

  • EPSS 0.11%
  • Veröffentlicht 17.04.2020 13:15:12
  • Zuletzt bearbeitet 21.11.2024 04:55:10

A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compromised user ...

  • EPSS 1.68%
  • Veröffentlicht 17.04.2020 13:15:12
  • Zuletzt bearbeitet 21.11.2024 04:54:58

A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could a...