PT-2020-12854 · Mitel · Mitel Micollab Awv

Tri Bui

·

Published

2020-06-10

·

Updated

2023-04-06

·

CVE-2020-11798

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mitel MiCollab AWV versions prior to 8.1.2.4 Mitel MiCollab AWV versions 9.x prior to 9.1.3
Description A Directory Traversal issue in the web conference component could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
Recommendations For versions prior to 8.1.2.4, update to version 8.1.2.4 or later. For versions 9.x prior to 9.1.3, update to version 9.1.3 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-11798

Affected Products

Mitel Micollab Awv