CVE-2022-36454: Medium severity mitel micollab vulnerability
Published Oct 25, 2022
·Updated
A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could allow the authenticated attacker to impersonate another user's name.
Affected Software
1 affected component
Mitel MiCollab<=9.5.0.101
Event History
Oct 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-36454.
2
What is the affected software?
The affected software is Mitel MiCollab through version 9.5.0.101.
3
What is the severity of CVE-2022-36454?
The severity of CVE-2022-36454 is medium with a severity score of 6.5.
4
What can an attacker do with this vulnerability?
An authenticated attacker could modify their profile parameters and impersonate another user's name.
5
How can I fix the vulnerability in Mitel MiCollab?
To fix the vulnerability, it is recommended to update Mitel MiCollab to a version beyond 9.5.0.101.