CVE-2020-24593: Input Validation
Published Sep 25, 2020
·Updated
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.
Affected Software
3 affected components
Mitel MiCloud Management Portal<=6.0
Mitel MiCloud Management Portal=6.1
Mitel MiCloud Management Portal=6.1-sp4
Event History
Sep 25, 2020
CVE Published
via MITRE·03:46 AM
Data Sourced
via MITRE·03:46 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24593?
The severity of CVE-2020-24593 is high with a severity value of 7.2.
2
How does CVE-2020-24593 affect Mitel MiCloud Management Portal?
CVE-2020-24593 affects Mitel MiCloud Management Portal versions 6.0, 6.1, and 6.1 SP4.
3
What is the vulnerability type of CVE-2020-24593?
The vulnerability type of CVE-2020-24593 is SQL Injection.
4
How can a remote attacker exploit CVE-2020-24593?
A remote attacker can exploit CVE-2020-24593 by conducting a SQL Injection attack.
5
Are there any mitigations available for CVE-2020-24593?
It is recommended to update to Mitel MiCloud Management Portal version 6.1 SP5.