Mitel Micollab Audio Web Video Conferencing vulnerabilities

6 known vulnerabilities affecting mitel/micollab_audio_web_video_conferencing.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-11797HIGHCVSS 7.5fixed in 8.1.2.4≥ 9.0, < 9.1.32020-08-26
CVE-2020-11797 [HIGH] CVE-2020-11797: An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mi An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gain access to unauthorized information due to insufficient access validation. A successful exploit could allow an attacker to access sensitive shared files.
nvd
CVE-2020-11798MEDIUMCVSS 5.3PoCfixed in 8.1.2.4≥ 9.0, < 9.1.32020-06-10
CVE-2020-11798 [MEDIUM] CWE-22 CVE-2020-11798: A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1 A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information
nvd
CVE-2019-19608CRITICALCVSS 9.8≤ 8.0.2.301≥ 8.1, ≤ 8.1.1.112020-03-02
CVE-2019-19608 [CRITICAL] CWE-89 CVE-2019-19608: A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1. A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the registeredList.cgi page. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.
nvd
CVE-2019-19607CRITICALCVSS 9.8≤ 8.0.2.301≥ 8.1, ≤ 8.1.1.112020-03-02
CVE-2019-19607 [CRITICAL] CWE-89 CVE-2019-19607: A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to insufficient input validation for the session parameter. A successful exploit could allow an attacker to extract sensitive information from the database and execute arbitrary scripts.
nvd
CVE-2019-19371MEDIUMCVSS 6.1≤ 8.0.2.301≥ 8.1, ≤ 8.1.1.112020-03-02
CVE-2019-19371 [MEDIUM] CWE-79 CVE-2019-19371: A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV b A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation in the join meeting interface. A successful exploit could allow an attacker to execute arbitrary scripts.
nvd
CVE-2019-12165CRITICALCVSS 9.8≥ 5.0, ≤ 5.0.5.7≥ 6.0, ≤ 6.0.0.61+3 more2019-05-29
CVE-2019-12165 [CRITICAL] CVE-2019-12165: MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability. Successful exploit of this vulnerability could allow an attacker to execute arbitrary system commands.
nvd