First published: Tue Aug 13 2024(Updated: )
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice MX-ONE | <7.6 | |
Mitel MiVoice MX-ONE | =7.6 | |
Mitel MiVoice MX-ONE | =7.6-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36446 is a vulnerability in the provisioning manager component of Mitel MiVoice MX-ONE through version 7.6 SP1 that allows authenticated attackers to bypass authentication due to improper access control.
Exploiting CVE-2024-36446 could enable an attacker to bypass the authorization schema, potentially leading to unauthorized access within the Mitel MiVoice MX-ONE systems.
Users of Mitel MiVoice MX-ONE versions 7.6 through 7.6 SP1 are affected by CVE-2024-36446.
To fix CVE-2024-36446, update your Mitel MiVoice MX-ONE software to the latest version that addresses this vulnerability.
CVE-2024-36446 is rated as a high severity vulnerability due to its potential to allow unauthorized access.