PT-2020-12853 · Mitel · Mitel Micollab Awv
Published
2020-08-26
·
Updated
2021-07-21
·
CVE-2020-11797
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mitel MiCollab AWV versions prior to 8.1.2.4
Mitel MiCollab AWV versions 9.x prior to 9.1.3
Description
The issue is related to an Authentication Bypass in the Published Area of the web conferencing component, which could allow an unauthenticated attacker to gain access to unauthorized information due to insufficient access validation. A successful exploit could allow an attacker to access sensitive shared files.
Recommendations
For versions prior to 8.1.2.4, update to version 8.1.2.4 or later.
For versions 9.x prior to 9.1.3, update to version 9.1.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mitel Micollab Awv