← Back

Mitel

mitel

134 CVEs • 128 products

Products (128)

Click to collapse
Toggle
Micollab
micollab
St14.2
st14.2
St 14.2
st_14.2
Cmg Suite
cmg_suite
6970 Firmware
6970_firmware
6920 Firmware
6920_firmware
6930 Firmware
6930_firmware
6940 Firmware
6940_firmware
6905 Firmware
6905_firmware
6910 Firmware
6910_firmware
Mivoice
mivoice
Mivoic Mx One
mivoic_mx-one
Mivoice 5000
mivoice_5000
St Firmware
st_firmware
Inattend
inattend
6863i Firmware
6863i_firmware
6865i Firmware
6865i_firmware
6867i Firmware
6867i_firmware
6869i Firmware
6869i_firmware
6873i Firmware
6873i_firmware
6863 Firmware
6863_firmware
6865 Firmware
6865_firmware
6867 Firmware
6867_firmware
6869 Firmware
6869_firmware
6873 Firmware
6873_firmware
Minet Firmware
minet_firmware
6940w Firmware
6940w_firmware
6930w Firmware
6930w_firmware
6920w Firmware
6920w_firmware
6915 Firmware
6915_firmware
Cx
cx
St
st
Mivoice 5330e
mivoice_5330e
Sip Dect
sip-dect
6863i
6865i
6867i
6869i
6873i
6920
6930
6940
6863
6865
6867
6869
6873
6970
6905
6910
Shoretel
shoretel

CVEs (134)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mitel
1Micollab
Jun 17, 2026
Dec 18, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an att...Show more
The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference information.Show less
1Mitel
1Micollab
Jun 17, 2026
Dec 18, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to gain access to a web conference due to insufficient access control for conference codes.
1Mitel
1Micollab
Jun 17, 2026
Dec 18, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to...Show more
The NuPoint Messenger Portal of Mitel MiCollab before 9.2 could allow an authenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to view and modify user data.Show less
1Mitel
1Micollab
Jun 17, 2026
Dec 18, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The SAS portal of Mitel MiCollab before 9.2 could allow an attacker to access user credentials due to improper input validation, aka SQL Injection.
1Mitel
1Micollab
Jun 17, 2026
Dec 18, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The AWV component of Mitel MiCollab before 9.2 could allow an attacker to view system information by sending arbitrary code due to improper input validation, aka XSS.
1Mitel
1Micontact Center Business
Jun 17, 2026
Dec 18, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization.
1Mitel
1Shoretel Firmware
Jun 17, 2026
Nov 9, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient vali...Show more
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.Show less
1Mitel
1Micontact Center Business
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain...Show more
The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.Show less
1Mitel
1Micloud Management Portal
Jun 17, 2026
Sep 25, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to retrieve sensitive information due to insufficient access control.
1Mitel
1Micloud Management Portal
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain acce...Show more
Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.Show less
1Mitel
1Micloud Management Portal
Jun 17, 2026
Sep 25, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.
1Mitel
1Micloud Management Portal
Jun 17, 2026
Sep 25, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.
1Mitel
1Mivoice Connect Client
Jun 17, 2026
Aug 26, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A...Show more
A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper rendering of chat messages. A successful exploit could allow an attacker to steal session cookies, perform directory traversal, and execute arbitrary scripts in the context of the Connect client.Show less
1Mitel
1Micollab Audio, Web & Video Conferencing
Jun 17, 2026
Aug 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gain access to unauthori...Show more
An Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an unauthenticated attacker to gain access to unauthorized information due to insufficient access validation. A successful exploit could allow an attacker to access sensitive shared files.Show less
1Mitel
1Micollab
Jun 17, 2026
Aug 26, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could a...Show more
The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could allow an attacker to access user information.Show less
1Mitel
1Micollab
Jun 17, 2026
Aug 26, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successfu...Show more
The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successful) could allow an attacker to gain access to sensitive information,Show less
1Mitel
116863 Firmware
6865 Firmware6867 Firmware+8 more
Jun 17, 2026
Aug 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed l...Show more
The Web UI component of Mitel MiVoice 6800 and 6900 series SIP Phones with firmware before 5.1.0.SP5 could allow an unauthenticated attacker to expose sensitive information due to improper memory handling during failed login attempts.Show less
1Mitel
1Micollab Audio, Web & Video Conferencing
Jun 17, 2026
Jun 10, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server vi...Show more
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.Show less
1Mitel
2Mivoice Connect
Shoretel Conference Web
Jun 17, 2026
May 7, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the P...Show more
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.Show less
1Mitel
1Mivoice Connect Client
Jun 17, 2026
Apr 17, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the...Show more
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an attacker to access the system with compromised user credentials.Show less