First published: Fri Sep 25 2020(Updated: )
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiCloud Management Portal | <=6.0 | |
Mitel MiCloud Management Portal | =6.1 | |
Mitel MiCloud Management Portal | =6.1-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24595 is a vulnerability in Mitel MiCloud Management Portal that could allow an attacker to retrieve sensitive information due to insufficient access control.
CVE-2020-24595 has a severity score of 5.3, which is considered medium.
An attacker can exploit CVE-2020-24595 by sending a crafted request to the Mitel MiCloud Management Portal.
Mitel MiCloud Management Portal versions 6.0, 6.1, and 6.1 SP4 are affected by CVE-2020-24595.
To fix CVE-2020-24595, it is recommended to upgrade to Mitel MiCloud Management Portal version 6.1 SP5 or later.