CVE-2021-3352: Critical severity Mitel MiContact Center Business vulnerability
The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without authorization due to improper handling of tokens.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3352?
CVE-2021-3352 is a vulnerability in Mitel MiContact Center Business SDK that allows an unauthenticated attacker to access and modify user data without authorization.
How severe is CVE-2021-3352?
CVE-2021-3352 has a severity rating of 9.1 (Critical).
Which versions of Mitel MiContact Center Business are affected by CVE-2021-3352?
Mitel MiContact Center Business versions 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 are affected.
How can an attacker exploit CVE-2021-3352?
An attacker can exploit CVE-2021-3352 by improperly handling tokens to access and modify user data without authorization.
Is there a fix for CVE-2021-3352?
Mitel has released security advisories and it is recommended to apply the necessary updates or patches provided by Mitel to fix CVE-2021-3352.