First published: Fri Apr 17 2020(Updated: )
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compromised user credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice Connect | <=19.1 | |
Mitel MiVoice Connect Client | <=214.100.1213.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this weak encryption vulnerability is CVE-2020-10377.
The severity of CVE-2020-10377 is critical with a severity value of 9.8.
Mitel MiVoice Connect Client versions up to and including 214.100.1213.0 are affected.
An unauthenticated attacker can exploit CVE-2020-10377 by gaining access to user credentials.
Yes, Mitel has released security advisories for CVE-2020-10377. You can find more information on their website.