Перейти к содержимому
Noroxi

Записи mitel

142 опубликованных записей вендора mitel.

Профиль для исследователя

Попали в KEV
8 · 5,6 %
С эксплойтом
8 · 5,6 %
Pre-auth RCE
41
С записью об исправлении
1,4 %
Медиана: публикация → KEV
85 дн.

Все записи

142 записей
  • CVE-2024-41713
    95Срочно

    A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 98 %

    mitel · micollab21 окт. 2024 г.

  • CVE-2022-26143
    95Срочно

    The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %

    mitel · micollab10 мар. 2022 г.

  • CVE-2014-0160
    90Срочно

    The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %

    openssl · openssl7 апр. 2014 г.

  • CVE-2022-29499
    85Срочно

    The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 55 %

    mitel · mivoice connect25 апр. 2022 г.

  • CVE-2024-41710
    70На этой неделе

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 42 %

    mitel · 6970 firmware12 авг. 2024 г.

  • CVE-2022-41223
    60На этой неделе

    The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injec

    СредняяCVSS 6,8KEVГотовый эксплойтEPSS 11 %

    mitel · mivoice connect21 нояб. 2022 г.

  • CVE-2022-40765
    60На этой неделе

    A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker wit

    СредняяCVSS 6,8KEVГотовый эксплойтEPSS 11 %

    mitel · mivoice connect21 нояб. 2022 г.

  • CVE-2024-35286
    59В плане

    A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection

    КритическаяCVSS 9,8Proof of conceptEPSS 66 %

    mitel · micollab21 окт. 2024 г.

  • CVE-2024-55550
    51В плане

    Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insu

    НизкаяCVSS 2,7KEVГотовый эксплойтEPSS 38 %

    mitel · micollab10 дек. 2024 г.

  • CVE-2018-5782
    45В плане

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    КритическаяCVSS 9,8Proof of conceptEPSS 19 %

    mitel · connect onsite14 мар. 2018 г.

  • CVE-2018-3639
    40В плане

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem

    СредняяCVSS 5,5Proof of conceptEPSS 61 %

    intel · atom c22 мая 2018 г.

  • CVE-2018-15497
    40В плане

    The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    mitel · mivoice 5330e firmware23 окт. 2018 г.

  • CVE-2018-19275
    40В плане

    The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    mitel · cmg suite2 апр. 2019 г.

  • CVE-2019-12165
    40В плане

    MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    mitel · micollab29 мая 2019 г.

  • CVE-2020-10211
    40В плане

    A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attack

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    mitel · mivoice connect17 апр. 2020 г.

  • CVE-2018-5779
    40В плане

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    mitel · connect onsite14 мар. 2018 г.

  • CVE-2021-26714
    40В плане

    The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and fold

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    mitel · micontact center enterprise29 мар. 2021 г.

  • CVE-2018-18286
    40В плане

    SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitel · cmg suite25 апр. 2019 г.

  • CVE-2018-18285
    40В плане

    SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitel · cmg suite25 апр. 2019 г.

  • CVE-2024-35314
    40В плане

    A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitel · micollab21 окт. 2024 г.

  • CVE-2018-5781
    40В плане

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitel · connect onsite14 мар. 2018 г.

  • CVE-2018-5780
    40В плане

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitel · connect onsite14 мар. 2018 г.

  • CVE-2019-19608
    40В плане

    A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attac

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitel · micollab audio\, web \& video conferencing2 мар. 2020 г.

  • CVE-2019-19607
    40В плане

    A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack d

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitel · micollab audio\, web \& video conferencing2 мар. 2020 г.

  • CVE-2020-24594
    39Наблюдать

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpu

    КритическаяCVSS 9,6Эксплойта нетEPSS 2 %

    mitel · micloud management portal25 сент. 2020 г.