Mitel

Mivoice Office 400

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 05.10.2026 08:34:38
  • Zuletzt bearbeitet 06.10.2026 15:18:12

DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Con...

  • EPSS 0.35%
  • Veröffentlicht 05.10.2026 08:33:36
  • Zuletzt bearbeitet 06.10.2026 15:18:12

This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TC...

  • EPSS 0.09%
  • Veröffentlicht 05.10.2026 08:32:14
  • Zuletzt bearbeitet 06.10.2026 15:18:12

DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately v...

  • EPSS 0.25%
  • Veröffentlicht 05.10.2026 08:30:54
  • Zuletzt bearbeitet 06.10.2026 15:18:12

DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application. The...

  • EPSS 0.25%
  • Veröffentlicht 05.10.2026 08:28:58
  • Zuletzt bearbeitet 06.10.2026 15:18:12

DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal li...

  • EPSS 0.31%
  • Veröffentlicht 05.10.2026 08:24:22
  • Zuletzt bearbeitet 06.10.2026 15:18:12

DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listen...

  • EPSS 0.22%
  • Veröffentlicht 05.10.2026 08:22:08
  • Zuletzt bearbeitet 06.10.2026 15:18:12

DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists...

  • EPSS 0.14%
  • Veröffentlicht 05.10.2026 08:17:15
  • Zuletzt bearbeitet 06.10.2026 15:18:12

DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs

  • EPSS 1.65%
  • Veröffentlicht 14.08.2023 19:15:13
  • Zuletzt bearbeitet 21.11.2024 08:15:05

A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.

  • EPSS 0.63%
  • Veröffentlicht 14.08.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 08:15:05

A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.