First published: Fri Dec 18 2020(Updated: )
The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to view the user information and application data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel Businesscti Enterprise | <6.4.11 | |
Mitel Businesscti Enterprise | >=7.0.0<7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27154 is a vulnerability in the chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 that allows an attacker to gain access to user information by sending arbitrary code.
CVE-2020-27154 affects Mitel BusinessCTI Enterprise versions before 6.4.11 and 7.x before 7.0.3 on Windows by allowing an attacker to gain access to user information.
CVE-2020-27154 has a severity rating of 8.8 (high).
To fix CVE-2020-27154, update Mitel BusinessCTI Enterprise to version 6.4.11 or higher, or version 7.0.3 or higher on Windows.
More information about CVE-2020-27154 can be found at the following reference: [https://www.mitel.com/support/security-advisories](https://www.mitel.com/support/security-advisories)