A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.
CVSS
No CVSS.
References
Configurations
History
30 May 2025, 01:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.mitel.com/support/security-advisories - Vendor Advisory | |
References | () https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0024 - Vendor Advisory | |
References | () https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin_24-0024-001-v2.pdf - Broken Link | |
First Time |
Mitel micontact Center Business
Mitel |
|
CPE | cpe:2.3:a:mitel:micontact_center_business:*:*:*:*:*:*:*:* |
03 Oct 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session. |
01 Oct 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-01 19:15
Updated : 2025-05-30 01:26
NVD link : CVE-2024-42514
Mitre link : CVE-2024-42514
JSON object : View
Products Affected
mitel
- micontact_center_business
CWE
No CWE.