CVE-2023-22854: Critical severity mitel micontact center business vulnerability
Published Feb 13, 2023
·Updated
The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information.
Affected Software
1 affected component
Mitel MiContact Center Business>=9.2.2.0<9.4.2.0
Event History
Feb 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-22854.
2
What is the severity level of CVE-2023-22854?
The severity level of CVE-2023-22854 is high with a severity value of 7.5.
3
What is the affected software for CVE-2023-22854?
The affected software for CVE-2023-22854 is Mitel MiContact Center Business server versions 9.2.2.0 through 9.4.1.0.
4
What could an attacker do with CVE-2023-22854?
An unauthenticated attacker could download arbitrary files and gain access to sensitive information.
5
How can CVE-2023-22854 be fixed?
To fix CVE-2023-22854, it is recommended to update Mitel MiContact Center Business server to version 9.4.2.0 or higher.