PT-2025-26736 · Mitel · Mitel Micontact Center Business

Published

2025-01-22

·

Updated

2025-06-24

·

CVE-2025-27827

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Mitel MiContact Center Business versions through 10.2.0.3
Description: A vulnerability in the legacy chat component could allow an unauthenticated attacker to conduct an information disclosure attack due to improper handling of session data. A successful exploit requires user interaction and could allow an attacker to access sensitive information, leading to unauthorized access to active chat rooms, reading chat data, and sending messages during an active chat session.
Recommendations: For Mitel MiContact Center Business versions through 10.2.0.3, consider disabling the legacy chat component until a patch is available to prevent exploitation. Restrict access to sensitive information and active chat rooms to minimize the risk of unauthorized access.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-13200
CVE-2025-27827

Affected Products

Mitel Micontact Center Business