Skip to content
Noroxi

mitel records

142 published records for vendor mitel.

All records

142 records
  • A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti

    CriticalCVSS 9.1KEVWeaponizedEPSS 98%

    mitel · micollabOct 21, 2024

  • The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    mitel · micollabMar 10, 2022

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    openssl · opensslApr 7, 2014

  • The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.

    CriticalCVSS 9.8KEVWeaponizedEPSS 55%

    mitel · mivoice connectApr 25, 2022

  • CVE-2024-41710
    70This week

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (

    HighCVSS 7.2KEVWeaponizedEPSS 42%

    mitel · 6970 firmwareAug 12, 2024

  • CVE-2022-41223
    60This week

    The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injec

    MediumCVSS 6.8KEVWeaponizedEPSS 11%

    mitel · mivoice connectNov 21, 2022

  • CVE-2022-40765
    60This week

    A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker wit

    MediumCVSS 6.8KEVWeaponizedEPSS 11%

    mitel · mivoice connectNov 21, 2022

  • A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection

    CriticalCVSS 9.8Proof of conceptEPSS 66%

    mitel · micollabOct 21, 2024

  • Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insu

    LowCVSS 2.7KEVWeaponizedEPSS 38%

    mitel · micollabDec 10, 2024

  • A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    mitel · connect onsiteMar 14, 2018

  • Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem

    MediumCVSS 5.5Proof of conceptEPSS 61%

    intel · atom cMay 22, 2018

  • The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.

    CriticalCVSS 9.8No exploitEPSS 5%

    mitel · mivoice 5330e firmwareOct 23, 2018

  • The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote

    CriticalCVSS 9.8No exploitEPSS 5%

    mitel · cmg suiteApr 2, 2019

  • MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (

    CriticalCVSS 9.8No exploitEPSS 3%

    mitel · micollabMay 29, 2019

  • A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attack

    CriticalCVSS 9.8No exploitEPSS 3%

    mitel · mivoice connectApr 17, 2020

  • A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    CriticalCVSS 9.8No exploitEPSS 3%

    mitel · connect onsiteMar 14, 2018

  • The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and fold

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    mitel · micontact center enterpriseMar 29, 2021

  • SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d

    CriticalCVSS 9.8No exploitEPSS 2%

    mitel · cmg suiteApr 25, 2019

  • SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d

    CriticalCVSS 9.8No exploitEPSS 2%

    mitel · cmg suiteApr 25, 2019

  • A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2

    CriticalCVSS 9.8No exploitEPSS 2%

    mitel · micollabOct 21, 2024

  • A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    CriticalCVSS 9.8No exploitEPSS 2%

    mitel · connect onsiteMar 14, 2018

  • A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    CriticalCVSS 9.8No exploitEPSS 2%

    mitel · connect onsiteMar 14, 2018

  • A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attac

    CriticalCVSS 9.8No exploitEPSS 2%

    mitel · micollab audio\, web \& video conferencingMar 2, 2020

  • A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack d

    CriticalCVSS 9.8No exploitEPSS 2%

    mitel · micollab audio\, web \& video conferencingMar 2, 2020

  • Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpu

    CriticalCVSS 9.6No exploitEPSS 2%

    mitel · micloud management portalSep 25, 2020