mitel kayıtları
mitel üreticisine ait 142 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 8 · %5,6
- Silahlaştırılmış
- 8 · %5,6
- Pre-auth RCE
- 41
- Düzeltme kaydı olan
- %1,4
- Yayından KEV’e ortanca
- 85 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')23
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-20 Improper Input Validation11
- CWE-94 Improper Control of Generation of Code ('Code Injection')9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
142 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2024-41713Silahlaştırılmış | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthentimitel · micollab · CWE-22 | Kritik9,1 | KEV | %98,1 | 21 Eki 2024 |
95Hemen | CVE-2022-26143Silahlaştırılmış | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers tomitel · micollab · CWE-306 | Kritik9,8 | KEV | %87,3 | 10 Mar 2022 |
90Hemen | CVE-2014-0160Silahlaştırılmış | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Yüksek7,5 | KEV | %100,0 | 7 Nis 2014 |
85Hemen | CVE-2022-29499Silahlaştırılmış | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.mitel · mivoice connect · CWE-20 | Kritik9,8 | KEV | %55,0 | 25 Nis 2022 |
70Bu hafta | CVE-2024-41710Silahlaştırılmış | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (mitel · 6970 firmware · CWE-88 | Yüksek7,2 | KEV | %41,6 | 12 Ağu 2024 |
60Bu hafta | CVE-2022-41223Silahlaştırılmış | The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injecmitel · mivoice connect · CWE-94 | Orta6,8 | KEV | %10,7 | 21 Kas 2022 |
60Bu hafta | CVE-2022-40765Silahlaştırılmış | A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker witmitel · mivoice connect · CWE-77 | Orta6,8 | KEV | %10,6 | 21 Kas 2022 |
59Planlayın | CVE-2024-35286Kavram kanıtı | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection mitel · micollab · CWE-89 | Kritik9,8 | — | %65,7 | 21 Eki 2024 |
51Planlayın | CVE-2024-55550Silahlaştırılmış | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insumitel · micollab · CWE-22 | Düşük2,7 | KEV | %38,2 | 10 Ara 2024 |
45Planlayın | CVE-2018-5782Kavram kanıtı | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Kritik9,8 | — | %18,7 | 14 Mar 2018 |
40Planlayın | CVE-2018-3639Kavram kanıtı | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Orta5,5 | — | %60,6 | 22 May 2018 |
40Planlayın | CVE-2018-15497İstismar yok | The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.mitel · mivoice 5330e firmware · CWE-119 | Kritik9,8 | — | %4,9 | 23 Eki 2018 |
40Planlayın | CVE-2018-19275İstismar yok | The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remotemitel · cmg suite · CWE-1188 | Kritik9,8 | — | %4,6 | 2 Nis 2019 |
40Planlayın | CVE-2019-12165İstismar yok | MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (mitel · micollab | Kritik9,8 | — | %3,4 | 29 May 2019 |
40Planlayın | CVE-2020-10211İstismar yok | A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attackmitel · mivoice connect · CWE-20 | Kritik9,8 | — | %3,0 | 17 Nis 2020 |
40Planlayın | CVE-2018-5779İstismar yok | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Kritik9,8 | — | %2,7 | 14 Mar 2018 |
40Planlayın | CVE-2021-26714Kavram kanıtı | The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and foldmitel · micontact center enterprise | Kritik9,8 | — | %2,5 | 29 Mar 2021 |
40Planlayın | CVE-2018-18286İstismar yok | SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack dmitel · cmg suite · CWE-89 | Kritik9,8 | — | %1,8 | 25 Nis 2019 |
40Planlayın | CVE-2018-18285İstismar yok | SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack dmitel · cmg suite · CWE-89 | Kritik9,8 | — | %1,8 | 25 Nis 2019 |
40Planlayın | CVE-2024-35314İstismar yok | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2mitel · micollab · CWE-94 | Kritik9,8 | — | %1,8 | 21 Eki 2024 |
40Planlayın | CVE-2018-5781İstismar yok | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Kritik9,8 | — | %1,7 | 14 Mar 2018 |
40Planlayın | CVE-2018-5780İstismar yok | A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and mitel · connect onsite · CWE-94 | Kritik9,8 | — | %1,7 | 14 Mar 2018 |
40Planlayın | CVE-2019-19608İstismar yok | A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attacmitel · micollab audio\, web \& video conferencing · CWE-89 | Kritik9,8 | — | %1,7 | 2 Mar 2020 |
40Planlayın | CVE-2019-19607İstismar yok | A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack dmitel · micollab audio\, web \& video conferencing · CWE-89 | Kritik9,8 | — | %1,7 | 2 Mar 2020 |
39İzleyin | CVE-2020-24594İstismar yok | Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpumitel · micloud management portal · CWE-79 | Kritik9,6 | — | %1,7 | 25 Eyl 2020 |
- CVE-2024-4171395Hemen
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %98mitel · micollab21 Eki 2024
- CVE-2022-2614395Hemen
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87mitel · micollab10 Mar 2022
- CVE-2014-016090Hemen
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100openssl · openssl7 Nis 2014
- CVE-2022-2949985Hemen
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %55mitel · mivoice connect25 Nis 2022
- CVE-2024-4171070Bu hafta
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %42mitel · 6970 firmware12 Ağu 2024
- CVE-2022-4122360Bu hafta
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injec
OrtaCVSS 6,8KEVSilahlaştırılmışEPSS %11mitel · mivoice connect21 Kas 2022
- CVE-2022-4076560Bu hafta
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker wit
OrtaCVSS 6,8KEVSilahlaştırılmışEPSS %11mitel · mivoice connect21 Kas 2022
- CVE-2024-3528659Planlayın
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection
KritikCVSS 9,8Kavram kanıtıEPSS %66mitel · micollab21 Eki 2024
- CVE-2024-5555051Planlayın
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insu
DüşükCVSS 2,7KEVSilahlaştırılmışEPSS %38mitel · micollab10 Ara 2024
- CVE-2018-578245Planlayın
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
KritikCVSS 9,8Kavram kanıtıEPSS %19mitel · connect onsite14 Mar 2018
- CVE-2018-363940Planlayın
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
OrtaCVSS 5,5Kavram kanıtıEPSS %61intel · atom c22 May 2018
- CVE-2018-1549740Planlayın
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality.
KritikCVSS 9,8İstismar yokEPSS %5mitel · mivoice 5330e firmware23 Eki 2018
- CVE-2018-1927540Planlayın
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote
KritikCVSS 9,8İstismar yokEPSS %5mitel · cmg suite2 Nis 2019
- CVE-2019-1216540Planlayın
MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (
KritikCVSS 9,8İstismar yokEPSS %3mitel · micollab29 May 2019
- CVE-2020-1021140Planlayın
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attack
KritikCVSS 9,8İstismar yokEPSS %3mitel · mivoice connect17 Nis 2020
- CVE-2018-577940Planlayın
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
KritikCVSS 9,8İstismar yokEPSS %3mitel · connect onsite14 Mar 2018
- CVE-2021-2671440Planlayın
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and fold
KritikCVSS 9,8Kavram kanıtıEPSS %3mitel · micontact center enterprise29 Mar 2021
- CVE-2018-1828640Planlayın
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d
KritikCVSS 9,8İstismar yokEPSS %2mitel · cmg suite25 Nis 2019
- CVE-2018-1828540Planlayın
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack d
KritikCVSS 9,8İstismar yokEPSS %2mitel · cmg suite25 Nis 2019
- CVE-2024-3531440Planlayın
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.2
KritikCVSS 9,8İstismar yokEPSS %2mitel · micollab21 Eki 2024
- CVE-2018-578140Planlayın
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
KritikCVSS 9,8İstismar yokEPSS %2mitel · connect onsite14 Mar 2018
- CVE-2018-578040Planlayın
A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and
KritikCVSS 9,8İstismar yokEPSS %2mitel · connect onsite14 Mar 2018
- CVE-2019-1960840Planlayın
A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attac
KritikCVSS 9,8İstismar yokEPSS %2mitel · micollab audio\, web \& video conferencing2 Mar 2020
- CVE-2019-1960740Planlayın
A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack d
KritikCVSS 9,8İstismar yokEPSS %2mitel · micollab audio\, web \& video conferencing2 Mar 2020
- CVE-2020-2459439İzleyin
Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient inpu
KritikCVSS 9,6İstismar yokEPSS %2mitel · micloud management portal25 Eyl 2020