CVE-2022-36453: High severity mitel micollab vulnerability
Published Oct 25, 2022
·Updated
A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authenticated attacker to control another extension number.
Affected Software
1 affected component
Mitel MiCollab>=9.1.3<=9.5.0.101
Event History
Oct 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-36453.
2
What is the severity of CVE-2022-36453?
The severity of CVE-2022-36453 is high with a CVSS score of 8.8.
3
How does CVE-2022-36453 affect Mitel MiCollab?
CVE-2022-36453 affects Mitel MiCollab versions 9.1.3 through 9.5.0.101.
4
What can an authenticated attacker do with CVE-2022-36453?
An authenticated attacker can modify their profile parameters and control another extension number.
5
How can I fix CVE-2022-36453?
Mitel has released security advisories and updates to address CVE-2022-36453. Please refer to Mitel's support website for more information.