PT-2024-29999 · Mitel · Mitel Micontact Center Business
Published
2024-10-01
·
Updated
2025-05-30
·
CVE-2024-42514
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mitel MiContact Center Business versions through 10.1.0.4
Description
A vulnerability in the legacy chat component could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.
Recommendations
For versions through 10.1.0.4, consider disabling the legacy chat component until a patch is available to prevent unauthorized access and messaging. Restrict access to sensitive information and monitor chat sessions for suspicious activity.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel Micontact Center Business