CVE Vulnerabilities

CVE-2021-3352

Published: Aug 13, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without authorization due to improper handling of tokens.

Affected Software

NameVendorStart VersionEnd Version
Micontact_center_businessMitel8.0.0.0 (including)8.1.4.1 (including)
Micontact_center_businessMitel9.0.0.0 (including)9.3.1.0 (including)

References