PT-2020-12853 · Mitel · Mitel Micollab Awv

Published

2020-08-26

·

Updated

2021-07-21

·

CVE-2020-11797

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mitel MiCollab AWV versions prior to 8.1.2.4 Mitel MiCollab AWV versions 9.x prior to 9.1.3
Description The issue is related to an Authentication Bypass in the Published Area of the web conferencing component, which could allow an unauthenticated attacker to gain access to unauthorized information due to insufficient access validation. A successful exploit could allow an attacker to access sensitive shared files.
Recommendations For versions prior to 8.1.2.4, update to version 8.1.2.4 or later. For versions 9.x prior to 9.1.3, update to version 9.1.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-11797

Affected Products

Mitel Micollab Awv