CVE-2017-16250: Infoleak
A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associated user names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16250?
CVE-2017-16250 is classified as a medium severity vulnerability due to the potential for user enumeration.
How do I fix CVE-2017-16250?
To fix CVE-2017-16250, upgrade your Mitel ST 14.2 system to a version later than GA28.
Who is affected by CVE-2017-16250?
CVE-2017-16250 affects users of Mitel ST 14.2, specifically those using release GA28 and earlier.
What impact does CVE-2017-16250 have?
The impact of CVE-2017-16250 allows attackers to identify valid user IDs and associated usernames through the API.
Is there an exploit for CVE-2017-16250 available?
While no specific exploit is publicly documented for CVE-2017-16250, the vulnerability's nature allows for potential enumeration attacks.