First published: Tue Oct 25 2022(Updated: )
A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authenticated attacker to control another extension number.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiCollab | >=9.1.3<=9.5.0.101 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-36453.
The severity of CVE-2022-36453 is high with a CVSS score of 8.8.
CVE-2022-36453 affects Mitel MiCollab versions 9.1.3 through 9.5.0.101.
An authenticated attacker can modify their profile parameters and control another extension number.
Mitel has released security advisories and updates to address CVE-2022-36453. Please refer to Mitel's support website for more information.