Записи mitel
142 опубликованных записей вендора mitel.
Профиль для исследователя
- Попали в KEV
- 8 · 5,6 %
- С эксплойтом
- 8 · 5,6 %
- Pre-auth RCE
- 41
- С записью об исправлении
- 1,4 %
- Медиана: публикация → KEV
- 85 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-20 Improper Input Validation11
- CWE-94 Improper Control of Generation of Code ('Code Injection')9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
142 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2024-41713Готовый эксплойт | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthentimitel · micollab · CWE-22 | Критическая9,1 | KEV | 98,1 % | 21 окт. 2024 г. |
95Срочно | CVE-2022-26143Готовый эксплойт | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers tomitel · micollab · CWE-306 | Критическая9,8 | KEV | 87,3 % | 10 мар. 2022 г. |
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
85Срочно | CVE-2022-29499Готовый эксплойт | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.mitel · mivoice connect · CWE-20 | Критическая9,8 | KEV | 55,0 % | 25 апр. 2022 г. |
70На этой неделе | CVE-2024-41710Готовый эксплойт | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (mitel · 6970 firmware · CWE-88 | Высокая7,2 | KEV | 41,6 % | 12 авг. 2024 г. |
60На этой неделе | CVE-2022-41223Готовый эксплойт | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injecmitel · mivoice connect · CWE-94 | Средняя6,8 | KEV | 10,7 % | 21 нояб. 2022 г. |
60На этой неделе | CVE-2022-40765Готовый эксплойт | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker witmitel · mivoice connect · CWE-77 | Средняя6,8 | KEV | 10,6 % | 21 нояб. 2022 г. |
59В плане | CVE-2024-35286Proof of concept | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection mitel · micollab · CWE-89 | Критическая9,8 | — | 65,7 % | 21 окт. 2024 г. |
51В плане | CVE-2024-55550Готовый эксплойт | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insumitel · micollab · CWE-22 | Низкая2,7 | KEV | 38,2 % | 10 дек. 2024 г. |
45В плане | CVE-2018-5782Proof of concept | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Критическая9,8 | — | 18,7 % | 14 мар. 2018 г. |
40В плане | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Средняя5,5 | — | 60,6 % | 22 мая 2018 г. |
40В плане | CVE-2018-15497Эксплойта нет | The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.mitel · mivoice 5330e firmware · CWE-119 | Критическая9,8 | — | 4,9 % | 23 окт. 2018 г. |
40В плане | CVE-2018-19275Эксплойта нет | The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remotemitel · cmg suite · CWE-1188 | Критическая9,8 | — | 4,6 % | 2 апр. 2019 г. |
40В плане | CVE-2019-12165Эксплойта нет | MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (mitel · micollab | Критическая9,8 | — | 3,4 % | 29 мая 2019 г. |
40В плане | CVE-2020-10211Эксплойта нет | A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attackmitel · mivoice connect · CWE-20 | Критическая9,8 | — | 3,0 % | 17 апр. 2020 г. |
40В плане | CVE-2018-5779Эксплойта нет | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Критическая9,8 | — | 2,7 % | 14 мар. 2018 г. |
40В плане | CVE-2021-26714Proof of concept | The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and foldmitel · micontact center enterprise | Критическая9,8 | — | 2,5 % | 29 мар. 2021 г. |
40В плане | CVE-2018-18286Эксплойта нет | SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack dmitel · cmg suite · CWE-89 | Критическая9,8 | — | 1,8 % | 25 апр. 2019 г. |
40В плане | CVE-2018-18285Эксплойта нет | SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack dmitel · cmg suite · CWE-89 | Критическая9,8 | — | 1,8 % | 25 апр. 2019 г. |
40В плане | CVE-2024-35314Эксплойта нет | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2mitel · micollab · CWE-94 | Критическая9,8 | — | 1,8 % | 21 окт. 2024 г. |
40В плане | CVE-2018-5781Эксплойта нет | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Критическая9,8 | — | 1,7 % | 14 мар. 2018 г. |
40В плане | CVE-2018-5780Эксплойта нет | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Критическая9,8 | — | 1,7 % | 14 мар. 2018 г. |
40В плане | CVE-2019-19608Эксплойта нет | A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attacmitel · micollab audio\, web \& video conferencing · CWE-89 | Критическая9,8 | — | 1,7 % | 2 мар. 2020 г. |
40В плане | CVE-2019-19607Эксплойта нет | A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack dmitel · micollab audio\, web \& video conferencing · CWE-89 | Критическая9,8 | — | 1,7 % | 2 мар. 2020 г. |
39Наблюдать | CVE-2020-24594Эксплойта нет | Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpumitel · micloud management portal · CWE-79 | Критическая9,6 | — | 1,7 % | 25 сент. 2020 г. |
- CVE-2024-4171395Срочно
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 98 %mitel · micollab21 окт. 2024 г.
- CVE-2022-2614395Срочно
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %mitel · micollab10 мар. 2022 г.
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2022-2949985Срочно
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 55 %mitel · mivoice connect25 апр. 2022 г.
- CVE-2024-4171070На этой неделе
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 42 %mitel · 6970 firmware12 авг. 2024 г.
- CVE-2022-4122360На этой неделе
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injec
СредняяCVSS 6,8KEVГотовый эксплойтEPSS 11 %mitel · mivoice connect21 нояб. 2022 г.
- CVE-2022-4076560На этой неделе
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker wit
СредняяCVSS 6,8KEVГотовый эксплойтEPSS 11 %mitel · mivoice connect21 нояб. 2022 г.
- CVE-2024-3528659В плане
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection
КритическаяCVSS 9,8Proof of conceptEPSS 66 %mitel · micollab21 окт. 2024 г.
- CVE-2024-5555051В плане
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insu
НизкаяCVSS 2,7KEVГотовый эксплойтEPSS 38 %mitel · micollab10 дек. 2024 г.
- CVE-2018-578245В плане
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
КритическаяCVSS 9,8Proof of conceptEPSS 19 %mitel · connect onsite14 мар. 2018 г.
- CVE-2018-363940В плане
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
СредняяCVSS 5,5Proof of conceptEPSS 61 %intel · atom c22 мая 2018 г.
- CVE-2018-1549740В плане
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mitel · mivoice 5330e firmware23 окт. 2018 г.
- CVE-2018-1927540В плане
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %mitel · cmg suite2 апр. 2019 г.
- CVE-2019-1216540В плане
MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mitel · micollab29 мая 2019 г.
- CVE-2020-1021140В плане
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attack
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mitel · mivoice connect17 апр. 2020 г.
- CVE-2018-577940В плане
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %mitel · connect onsite14 мар. 2018 г.
- CVE-2021-2671440В плане
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and fold
КритическаяCVSS 9,8Proof of conceptEPSS 3 %mitel · micontact center enterprise29 мар. 2021 г.
- CVE-2018-1828640В плане
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitel · cmg suite25 апр. 2019 г.
- CVE-2018-1828540В плане
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitel · cmg suite25 апр. 2019 г.
- CVE-2024-3531440В плане
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitel · micollab21 окт. 2024 г.
- CVE-2018-578140В плане
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitel · connect onsite14 мар. 2018 г.
- CVE-2018-578040В плане
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitel · connect onsite14 мар. 2018 г.
- CVE-2019-1960840В плане
A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attac
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitel · micollab audio\, web \& video conferencing2 мар. 2020 г.
- CVE-2019-1960740В плане
A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack d
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitel · micollab audio\, web \& video conferencing2 мар. 2020 г.
- CVE-2020-2459439Наблюдать
Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpu
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %mitel · micloud management portal25 сент. 2020 г.