CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-3352

CVSS 9.1v3.1pub. 2021-08-13upd. 2024-11-21

The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without authorization due to improper handling of tokens.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Mitel Micontact Center Business

    APP
    Mitel
    8.0.0.0 – 8.1.4.19.0.0.0 – 9.3.1.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-67823HIGH8.2same product

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mit...

CVE-2024-42514HIGH8.1same product

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow a...

CVE-2024-28069HIGH7.5same product

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow a...

CVE-2023-22854HIGH7.5same product

The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthen...

CVE-2020-24692HIGH7.1same product

The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitra...