PT-2020-16642 · Mitel · Mitel Businesscti Enterprise Client
Published
2020-12-18
·
Updated
2020-12-21
·
CVE-2020-27154
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mitel BusinessCTI Enterprise (MBC-E) Client for Windows versions prior to 6.4.11
Mitel BusinessCTI Enterprise (MBC-E) Client for Windows versions 7.x prior to 7.0.3
Description
The issue is related to improper input validation in the chat window, allowing an attacker to send arbitrary code and potentially gain access to user information and application data. A successful exploit could allow an attacker to view sensitive data.
Recommendations
For versions prior to 6.4.11, update to version 6.4.11 or later to resolve the issue.
For versions 7.x prior to 7.0.3, update to version 7.0.3 or later to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel Businesscti Enterprise Client