CVE-2021-37586: Input Validation
The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Administrator rights) to replay a previously recorded conversation of another tenant due to insufficient validation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-37586?
CVE-2021-37586 is a vulnerability that allows a user with Administrator rights to replay a previously recorded conversation of another tenant in Mitel Interaction Recording Multitenancy systems before version 6.7.
What is the severity of CVE-2021-37586?
CVE-2021-37586 has a severity level of medium, with a CVSS score of 4.9.
Which software versions are affected by CVE-2021-37586?
Mitel Interaction Recording Multitenancy systems before version 6.7 are affected by CVE-2021-37586.
How can a user exploit CVE-2021-37586?
A user with Administrator rights can exploit CVE-2021-37586 by replaying a previously recorded conversation of another tenant due to insufficient validation.
Is there a Mitel security advisory for CVE-2021-37586?
Yes, Mitel has released a security advisory for CVE-2021-37586. You can find it at the following link: [Mitel Security Advisories](https://www.mitel.com/support/security-advisories)