PT-2021-19651 · Mitel · Mitel Micollab
Published
2021-08-13
·
Updated
2022-05-03
·
CVE-2021-32071
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Mitel MiCollab versions prior to 9.3
Description:
The issue is related to improper access control in the MiCollab Client service, allowing an unauthenticated user to gain system access. A successful exploit could allow an attacker to view and modify application data, and cause a denial of service for users.
Recommendations:
For versions prior to 9.3, update to version 9.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the MiCollab Client service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mitel Micollab