HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-39289

CVSS 7.5v3.1pub. 2023-08-25upd. 2024-11-21

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Mitel Mivoice Connect

    APP
    Mitel
    ≤ 9.6.2208.101
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-29499CRITICAL9.8⚠ KEVPL ✓same product

RCE w komponencie Service Appliance Mitel MiVoice Connect

CVE-2023-32748CRITICAL9.8PL ✓same product

Mitel MiVoice Connect — obejście uwierzytelniania w komponencie Linux DVS

CVE-2023-31457CRITICAL9.8PL ✓same product

Mitel MiVoice Connect — ominięcie autoryzacji w komponencie Headquarters

CVE-2023-31458CRITICAL9.8PL ✓same product

Mitel MiVoice Connect – pominięcie uwierzytelnienia w Edge Gateway

CVE-2020-10211CRITICAL9.8PL ✓same product

RCE w komponencie UCB Mitel MiVoice Connect — brak walidacji parametrów URL