First published: Fri Apr 17 2020(Updated: )
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel Connect | <=19.1 | |
Mitel MiVoice Connect Client | <=214.100.1213.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10211 is a remote code execution vulnerability in the UCB component of Mitel MiVoice Connect before version 19.1 SP1.
CVE-2020-10211 allows an unauthenticated remote attacker to execute arbitrary scripts by exploiting insufficient validation of URL parameters.
CVE-2020-10211 has a severity rating of 9.8 (Critical).
Mitel MiVoice Connect before version 19.1 SP1 and Mitel MiVoice Connect Client before version 214.100.1213.0 are affected by CVE-2020-10211.
To fix CVE-2020-10211, it is recommended to update to Mitel MiVoice Connect version 19.1 SP1 or later, and Mitel MiVoice Connect Client version 214.100.1213.0 or later.