First published: Tue Apr 02 2019(Updated: )
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel Cmg Suite | <8.4 | |
Mitel Cmg Suite | =8.4 | |
Mitel Cmg Suite | =8.4-sp2 | |
Mitel InAttend | <2.5 | |
Mitel InAttend | =2.5 | |
Mitel InAttend | =2.5-sp1 | |
Mitel InAttend | =2.5-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19275 is considered to have a high severity due to the risk of unauthorized access and potential impact to system confidentiality, integrity, and availability.
To fix CVE-2018-19275, change the default password used by the BluStar component in Mitel InAttend and CMG Suite to a strong, unique password.
CVE-2018-19275 affects Mitel InAttend versions prior to 2.5 SP3 and CMG Suite versions prior to 8.4 SP3.
If exploited, CVE-2018-19275 could allow remote attackers to gain unauthorized access and execute arbitrary scripts on the affected systems.
The primary workaround for CVE-2018-19275 is to immediately change any default passwords configured in the affected Mitel products.