CVE-2020-10377: Weak Encryption
Published Apr 17, 2020
·Updated
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compromised user credentials.
Affected Software
2 affected components
Mitel MiVoice Connect<=19.1
Mitel MiVoice Connect Client<=214.100.1213.0
Event History
Apr 17, 2020
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this weak encryption vulnerability?
The vulnerability ID of this weak encryption vulnerability is CVE-2020-10377.
2
What is the severity of CVE-2020-10377?
The severity of CVE-2020-10377 is critical with a severity value of 9.8.
3
What software versions are affected by CVE-2020-10377?
Mitel MiVoice Connect Client versions up to and including 214.100.1213.0 are affected.
4
How can an unauthenticated attacker exploit CVE-2020-10377?
An unauthenticated attacker can exploit CVE-2020-10377 by gaining access to user credentials.
5
Are there any security advisories related to CVE-2020-10377?
Yes, Mitel has released security advisories for CVE-2020-10377. You can find more information on their website.