CVE Vulnerabilities

CVE-2021-3352

Published: Aug 13, 2021 | Modified: Aug 25, 2021
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without authorization due to improper handling of tokens.

Affected Software

Name Vendor Start Version End Version
Micontact_center_business Mitel 8.0.0.0 (including) 8.1.4.1 (including)
Micontact_center_business Mitel 9.0.0.0 (including) 9.3.1.0 (including)

References