CVE-2021-3176
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The chat window of the Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.15 and 7.x before 7.1.2 could allow an attacker to gain access to user information by sending certain code, due to improper input validation of http links. A successful exploit could allow an attacker to view user information and application data.
La ventana de chat de Mitel BusinessCTI Enterprise (MBC-E) Client para Windows versiones anteriores a 6.4.15 y versiones 7.x anteriores a 7.1.2, podría permitir a un atacante conseguir acceso a la información del usuario mediante el envío de determinado código, debido a una comprobación inapropiada de la entrada de enlaces http. Un explotación con éxito podría permitir a un atacante visualizar la información del usuario y los datos de la aplicación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-19 CVE Reserved
- 2021-01-29 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mitel.com/support/security-advisories | 2021-02-05 | |
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-21-0001 | 2021-02-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitel Search vendor "Mitel" | Businesscti Enterprise Search vendor "Mitel" for product "Businesscti Enterprise" | < 6.4.15 Search vendor "Mitel" for product "Businesscti Enterprise" and version " < 6.4.15" | windows |
Affected
| ||||||
Mitel Search vendor "Mitel" | Businesscti Enterprise Search vendor "Mitel" for product "Businesscti Enterprise" | >= 7.0 < 7.1.2 Search vendor "Mitel" for product "Businesscti Enterprise" and version " >= 7.0 < 7.1.2" | windows |
Affected
|