PT-2021-19651 · Mitel · Mitel Micollab

Published

2021-08-13

·

Updated

2022-05-03

·

CVE-2021-32071

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mitel MiCollab versions prior to 9.3
Description: The issue is related to improper access control in the MiCollab Client service, allowing an unauthenticated user to gain system access. A successful exploit could allow an attacker to view and modify application data, and cause a denial of service for users.
Recommendations: For versions prior to 9.3, update to version 9.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the MiCollab Client service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-32071

Affected Products

Mitel Micollab