A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.
CVSS
No CVSS.
References
Configurations
History
30 May 2025, 01:26
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mitel micontact Center Business
Mitel |
|
| CPE | cpe:2.3:a:mitel:micontact_center_business:*:*:*:*:*:*:*:* | |
| References | () https://www.mitel.com/support/security-advisories - Vendor Advisory | |
| References | () https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0024 - Vendor Advisory | |
| References | () https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin_24-0024-001-v2.pdf - Broken Link |
03 Oct 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session. |
01 Oct 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-10-01 19:15
Updated : 2025-05-30 01:26
NVD link : CVE-2024-42514
Mitre link : CVE-2024-42514
JSON object : View
Products Affected
mitel
- micontact_center_business
CWE
No CWE.
