CVE-2024-28069
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive information and potentially conduct unauthorized actions within the vulnerable component.
Una vulnerabilidad en el componente de chat heredado de Mitel MiContact Center Business hasta la versión 10.0.0.4 podría permitir que un atacante no autenticado lleve a cabo un ataque de divulgación de información debido a una configuración incorrecta. Un exploit exitoso podría permitir a un atacante acceder a información confidencial y potencialmente realizar acciones no autorizadas dentro del componente vulnerable.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-03-01 CVE Reserved
- 2024-03-16 CVE Published
- 2025-03-18 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-922: Insecure Storage of Sensitive Information
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0001 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitel Search vendor "Mitel" | Micontact Center Business Search vendor "Mitel" for product "Micontact Center Business" | * | - |
Affected
|