PT-2025-26736 · Mitel · Mitel Micontact Center Business
Published
2025-01-22
·
Updated
2025-06-24
·
CVE-2025-27827
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Mitel MiContact Center Business versions through 10.2.0.3
Description:
A vulnerability in the legacy chat component could allow an unauthenticated attacker to conduct an information disclosure attack due to improper handling of session data. A successful exploit requires user interaction and could allow an attacker to access sensitive information, leading to unauthorized access to active chat rooms, reading chat data, and sending messages during an active chat session.
Recommendations:
For Mitel MiContact Center Business versions through 10.2.0.3, consider disabling the legacy chat component until a patch is available to prevent exploitation. Restrict access to sensitive information and active chat rooms to minimize the risk of unauthorized access.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel Micontact Center Business