mitel records
142 published records for vendor mitel.
Researcher profile
- Entered KEV
- 8 · 5.6%
- Weaponized
- 8 · 5.6%
- Pre-auth RCE
- 41
- With a fix record
- 1.4%
- Median publish → KEV
- 85 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-20 Improper Input Validation11
- CWE-94 Improper Control of Generation of Code ('Code Injection')9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
The weakness classes this vendor ships most often: where to look.
CWEAll records
142 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2024-41713Weaponized | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthentimitel · micollab · CWE-22 | Critical9.1 | KEV | 98.1% | Oct 21, 2024 |
95Now | CVE-2022-26143Weaponized | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers tomitel · micollab · CWE-306 | Critical9.8 | KEV | 87.3% | Mar 10, 2022 |
90Now | CVE-2014-0160Weaponized | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | High7.5 | KEV | 100.0% | Apr 7, 2014 |
85Now | CVE-2022-29499Weaponized | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.mitel · mivoice connect · CWE-20 | Critical9.8 | KEV | 55.0% | Apr 25, 2022 |
70This week | CVE-2024-41710Weaponized | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (mitel · 6970 firmware · CWE-88 | High7.2 | KEV | 41.6% | Aug 12, 2024 |
60This week | CVE-2022-41223Weaponized | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injecmitel · mivoice connect · CWE-94 | Medium6.8 | KEV | 10.7% | Nov 21, 2022 |
60This week | CVE-2022-40765Weaponized | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker witmitel · mivoice connect · CWE-77 | Medium6.8 | KEV | 10.6% | Nov 21, 2022 |
59Plan | CVE-2024-35286Proof of concept | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection mitel · micollab · CWE-89 | Critical9.8 | — | 65.7% | Oct 21, 2024 |
51Plan | CVE-2024-55550Weaponized | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insumitel · micollab · CWE-22 | Low2.7 | KEV | 38.2% | Dec 10, 2024 |
45Plan | CVE-2018-5782Proof of concept | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Critical9.8 | — | 18.7% | Mar 14, 2018 |
40Plan | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Medium5.5 | — | 60.6% | May 22, 2018 |
40Plan | CVE-2018-15497No exploit | The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.mitel · mivoice 5330e firmware · CWE-119 | Critical9.8 | — | 4.9% | Oct 23, 2018 |
40Plan | CVE-2018-19275No exploit | The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remotemitel · cmg suite · CWE-1188 | Critical9.8 | — | 4.6% | Apr 2, 2019 |
40Plan | CVE-2019-12165No exploit | MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (mitel · micollab | Critical9.8 | — | 3.4% | May 29, 2019 |
40Plan | CVE-2020-10211No exploit | A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attackmitel · mivoice connect · CWE-20 | Critical9.8 | — | 3.0% | Apr 17, 2020 |
40Plan | CVE-2018-5779No exploit | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Critical9.8 | — | 2.7% | Mar 14, 2018 |
40Plan | CVE-2021-26714Proof of concept | The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and foldmitel · micontact center enterprise | Critical9.8 | — | 2.5% | Mar 29, 2021 |
40Plan | CVE-2018-18286No exploit | SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack dmitel · cmg suite · CWE-89 | Critical9.8 | — | 1.8% | Apr 25, 2019 |
40Plan | CVE-2018-18285No exploit | SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack dmitel · cmg suite · CWE-89 | Critical9.8 | — | 1.8% | Apr 25, 2019 |
40Plan | CVE-2024-35314No exploit | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2mitel · micollab · CWE-94 | Critical9.8 | — | 1.8% | Oct 21, 2024 |
40Plan | CVE-2018-5781No exploit | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Critical9.8 | — | 1.7% | Mar 14, 2018 |
40Plan | CVE-2018-5780No exploit | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Critical9.8 | — | 1.7% | Mar 14, 2018 |
40Plan | CVE-2019-19608No exploit | A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attacmitel · micollab audio\, web \& video conferencing · CWE-89 | Critical9.8 | — | 1.7% | Mar 2, 2020 |
40Plan | CVE-2019-19607No exploit | A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack dmitel · micollab audio\, web \& video conferencing · CWE-89 | Critical9.8 | — | 1.7% | Mar 2, 2020 |
39Monitor | CVE-2020-24594No exploit | Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpumitel · micloud management portal · CWE-79 | Critical9.6 | — | 1.7% | Sep 25, 2020 |
- CVE-2024-4171395Now
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti
CriticalCVSS 9.1KEVWeaponizedEPSS 98%mitel · micollabOct 21, 2024
- CVE-2022-2614395Now
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to
CriticalCVSS 9.8KEVWeaponizedEPSS 87%mitel · micollabMar 10, 2022
- CVE-2014-016090Now
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
HighCVSS 7.5KEVWeaponizedEPSS 100%openssl · opensslApr 7, 2014
- CVE-2022-2949985Now
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.
CriticalCVSS 9.8KEVWeaponizedEPSS 55%mitel · mivoice connectApr 25, 2022
- CVE-2024-4171070This week
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (
HighCVSS 7.2KEVWeaponizedEPSS 42%mitel · 6970 firmwareAug 12, 2024
- CVE-2022-4122360This week
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injec
MediumCVSS 6.8KEVWeaponizedEPSS 11%mitel · mivoice connectNov 21, 2022
- CVE-2022-4076560This week
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker wit
MediumCVSS 6.8KEVWeaponizedEPSS 11%mitel · mivoice connectNov 21, 2022
- CVE-2024-3528659Plan
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection
CriticalCVSS 9.8Proof of conceptEPSS 66%mitel · micollabOct 21, 2024
- CVE-2024-5555051Plan
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insu
LowCVSS 2.7KEVWeaponizedEPSS 38%mitel · micollabDec 10, 2024
- CVE-2018-578245Plan
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
CriticalCVSS 9.8Proof of conceptEPSS 19%mitel · connect onsiteMar 14, 2018
- CVE-2018-363940Plan
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
MediumCVSS 5.5Proof of conceptEPSS 61%intel · atom cMay 22, 2018
- CVE-2018-1549740Plan
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.
CriticalCVSS 9.8No exploitEPSS 5%mitel · mivoice 5330e firmwareOct 23, 2018
- CVE-2018-1927540Plan
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote
CriticalCVSS 9.8No exploitEPSS 5%mitel · cmg suiteApr 2, 2019
- CVE-2019-1216540Plan
MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (
CriticalCVSS 9.8No exploitEPSS 3%mitel · micollabMay 29, 2019
- CVE-2020-1021140Plan
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attack
CriticalCVSS 9.8No exploitEPSS 3%mitel · mivoice connectApr 17, 2020
- CVE-2018-577940Plan
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
CriticalCVSS 9.8No exploitEPSS 3%mitel · connect onsiteMar 14, 2018
- CVE-2021-2671440Plan
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and fold
CriticalCVSS 9.8Proof of conceptEPSS 3%mitel · micontact center enterpriseMar 29, 2021
- CVE-2018-1828640Plan
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d
CriticalCVSS 9.8No exploitEPSS 2%mitel · cmg suiteApr 25, 2019
- CVE-2018-1828540Plan
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d
CriticalCVSS 9.8No exploitEPSS 2%mitel · cmg suiteApr 25, 2019
- CVE-2024-3531440Plan
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2
CriticalCVSS 9.8No exploitEPSS 2%mitel · micollabOct 21, 2024
- CVE-2018-578140Plan
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
CriticalCVSS 9.8No exploitEPSS 2%mitel · connect onsiteMar 14, 2018
- CVE-2018-578040Plan
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
CriticalCVSS 9.8No exploitEPSS 2%mitel · connect onsiteMar 14, 2018
- CVE-2019-1960840Plan
A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attac
CriticalCVSS 9.8No exploitEPSS 2%mitel · micollab audio\, web \& video conferencingMar 2, 2020
- CVE-2019-1960740Plan
A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack d
CriticalCVSS 9.8No exploitEPSS 2%mitel · micollab audio\, web \& video conferencingMar 2, 2020
- CVE-2020-2459439Monitor
Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpu
CriticalCVSS 9.6No exploitEPSS 2%mitel · micloud management portalSep 25, 2020