CVE-2020-24592: Medium severity mitel micloud management portal vulnerability
Published Sep 25, 2020
·Updated
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.
Affected Software
3 affected components
Mitel MiCloud Management Portal<=6.0
Mitel MiCloud Management Portal=6.1
Mitel MiCloud Management Portal=6.1-sp4
Event History
Sep 25, 2020
CVE Published
via MITRE·03:44 AM
Data Sourced
via MITRE·03:44 AM
Description
Frequently Asked Questions
1
What is CVE-2020-24592?
CVE-2020-24592 is a vulnerability in Mitel MiCloud Management Portal before version 6.1 SP5 that could allow an attacker to view system information.
2
What is the severity of CVE-2020-24592?
The severity of CVE-2020-24592 is medium, with a CVSS score of 5.3.
3
How can an attacker exploit CVE-2020-24592?
An attacker can exploit CVE-2020-24592 by sending a crafted request to the Mitel MiCloud Management Portal.
4
Which software versions are affected by CVE-2020-24592?
Mitel MiCloud Management Portal versions 6.0, 6.1, and 6.1 SP4 are affected by CVE-2020-24592.
5
How can I fix CVE-2020-24592?
To fix CVE-2020-24592, it is recommended to update the Mitel MiCloud Management Portal to version 6.1 SP5.