CVE-2020-24595: Medium severity mitel micloud management portal vulnerability
Published Sep 25, 2020
·Updated
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.
Affected Software
3 affected components
Mitel MiCloud Management Portal<=6.0
Mitel MiCloud Management Portal=6.1
Mitel MiCloud Management Portal=6.1-sp4
Event History
Sep 25, 2020
CVE Published
via MITRE·03:47 AM
Data Sourced
via MITRE·03:47 AM
Description
Frequently Asked Questions
1
What is CVE-2020-24595?
CVE-2020-24595 is a vulnerability in Mitel MiCloud Management Portal that could allow an attacker to retrieve sensitive information due to insufficient access control.
2
What is the severity of CVE-2020-24595?
CVE-2020-24595 has a severity score of 5.3, which is considered medium.
3
How can an attacker exploit CVE-2020-24595?
An attacker can exploit CVE-2020-24595 by sending a crafted request to the Mitel MiCloud Management Portal.
4
Which versions of Mitel MiCloud Management Portal are affected by CVE-2020-24595?
Mitel MiCloud Management Portal versions 6.0, 6.1, and 6.1 SP4 are affected by CVE-2020-24595.
5
How can I fix CVE-2020-24595?
To fix CVE-2020-24595, it is recommended to upgrade to Mitel MiCloud Management Portal version 6.1 SP5 or later.