← Back

Mitel

mitel

134 CVEs • 128 products

Products (128)

Click to collapse
Toggle
Micollab
micollab
St14.2
st14.2
St 14.2
st_14.2
Cmg Suite
cmg_suite
6970 Firmware
6970_firmware
6920 Firmware
6920_firmware
6930 Firmware
6930_firmware
6940 Firmware
6940_firmware
6905 Firmware
6905_firmware
6910 Firmware
6910_firmware
Mivoice
mivoice
Mivoic Mx One
mivoic_mx-one
Mivoice 5000
mivoice_5000
St Firmware
st_firmware
Inattend
inattend
6863i Firmware
6863i_firmware
6865i Firmware
6865i_firmware
6867i Firmware
6867i_firmware
6869i Firmware
6869i_firmware
6873i Firmware
6873i_firmware
6863 Firmware
6863_firmware
6865 Firmware
6865_firmware
6867 Firmware
6867_firmware
6869 Firmware
6869_firmware
6873 Firmware
6873_firmware
Minet Firmware
minet_firmware
6940w Firmware
6940w_firmware
6930w Firmware
6930w_firmware
6920w Firmware
6920w_firmware
6915 Firmware
6915_firmware
Cx
cx
St
st
Mivoice 5330e
mivoice_5330e
Sip Dect
sip-dect
6863i
6865i
6867i
6869i
6873i
6920
6930
6940
6863
6865
6867
6869
6873
6970
6905
6910
Shoretel
shoretel

CVEs (134)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mitel
1Micontact Center Business
Jun 17, 2026
Oct 1, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A...Show more
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.Show less
1Mitel
1Mivoice Mx One
Jun 17, 2026
Aug 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow...Show more
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.Show less
1Mitel
156863i Sip Firmware
6865i Sip Firmware6867i Sip Firmware+12 more
Jun 17, 2026
Aug 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege...Show more
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system.Show less
1Mitel
16869i Sip Firmware
Jun 17, 2026
Jun 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpg...Show more
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.Show less
1Mitel
16869i Sip Firmware
Jun 17, 2026
Jun 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoin...Show more
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is subsequently written to disk. During boot, the hostname parameter is executed as part of a series of shell commands. Attackers can achieve remote code execution in the root context by placing shell metacharacters in the hostname parameter.Show less
1Mitel
1Micontact Center Business
Jun 17, 2026
May 29, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input...Show more
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation.Show less
1Mitel
1Micontact Center Business
Jun 17, 2026
May 29, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validati...Show more
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation.Show less
1Mitel
146905 Firmware
6910 Firmware6915 Firmware+11 more
Jun 17, 2026
Apr 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
1Mitel
1Micontact Center Business
Jun 17, 2026
Mar 16, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input...Show more
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. A successful exploit could allow an attacker to access sensitive information and gain unauthorized access.Show less
1Mitel
1Micontact Center Business
Jun 17, 2026
Mar 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A succes...Show more
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive information and potentially conduct unauthorized actions within the vulnerable component.Show less
1Mitel
1Unify Openscape Xpressions Webassistant
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
1Mitel
1Unify Openscape Xpressions Webassistant
Jun 17, 2026
Feb 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
1Mitel
1Connect Mobility Router
Jun 17, 2026
Sep 14, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient req...Show more
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.Show less
1Mitel
1Mivoice Connect
Jun 17, 2026
Sep 14, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient req...Show more
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.Show less
1Mitel
1Mivoice Connect
Jun 17, 2026
Aug 25, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper...Show more
A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.Show less
1Mitel
1Mivoice Connect
Jun 17, 2026
Aug 25, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to im...Show more
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.Show less
1Mitel
1Mivoice Connect
Jun 17, 2026
Aug 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A suc...Show more
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information.Show less
1Mitel
1Mivoice Connect
Jun 17, 2026
Aug 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argum...Show more
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.Show less
1Mitel
1Mivoice Connect
Jun 17, 2026
Aug 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argum...Show more
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.Show less
1Mitel
2Mivoice Office 400
Mivoice Office 400 Smb Controller Firmware
Jun 17, 2026
Aug 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.