CVE-2020-10211
 
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information.
Una vulnerabilidad de ejecución de código remota en el componente UCB de Mitel MiVoice Connect versiones anteriores a 19.1, SP1, podría permitir a un atacante no autenticado remoto ejecutar scripts arbitrarios debido a una comprobación no suficiente de los parámetros de la URL. Una explotación con éxito podría permitir a un atacante acceder a información confidencial.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-03-06 CVE Reserved
- 2020-04-17 CVE Published
- 2024-05-27 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mitel.com/support/security-advisories | 2020-04-23 | |
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-20-0004 | 2020-04-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitel Search vendor "Mitel" | Mivoice Connect Search vendor "Mitel" for product "Mivoice Connect" | <= 19.1 Search vendor "Mitel" for product "Mivoice Connect" and version " <= 19.1" | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | Mivoice Connect Client Search vendor "Mitel" for product "Mivoice Connect Client" | <= 214.100.1213.0 Search vendor "Mitel" for product "Mivoice Connect Client" and version " <= 214.100.1213.0" | - |
Affected
|