CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2020-10211

CVSS 9.8v3.1pub. 2020-04-17upd. 2025-11-03

A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mitel Mivoice Connect

    APP
    Mitel
    < 22.11.4900.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-29499CRITICAL9.8⚠ KEVPL ✓same product

RCE w komponencie Service Appliance Mitel MiVoice Connect

CVE-2023-32748CRITICAL9.8PL ✓same product

Mitel MiVoice Connect — obejście uwierzytelniania w komponencie Linux DVS

CVE-2023-31458CRITICAL9.8PL ✓same product

Mitel MiVoice Connect – pominięcie uwierzytelnienia w Edge Gateway

CVE-2023-31457CRITICAL9.8PL ✓same product

Mitel MiVoice Connect — ominięcie autoryzacji w komponencie Headquarters

CVE-2023-39289HIGH7.5same product

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could a...