Mitel
Mitel Micontact Center Business: vulnerabilidades y CVE
Mitel Micontact Center Business tiene 13 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-67823 | Alta (8.2) | 0.34% | — | 15 ene 2026 | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack… |
| CVE-2025-27828 | Alta (7.1) | 0.41% | — | 24 jun 2025 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4, 10.1.0.0 through 10.1.0.5, and 10.2.0.0 through 10.2.0.4 could allow an unauthenticated attacker to conduct a reflected… |
| CVE-2025-27827 | Alta (7.1) | 0.35% | — | 24 jun 2025 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper handling of session… |
| CVE-2024-42514 | Alta (8.1) | 0.45% | — | 1 oct 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks.… |
| CVE-2024-35284 | Media (5.4) | 0.25% | — | 29 may 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input… |
| CVE-2024-35283 | Media (6.1) | 0.26% | — | 29 may 2024 | A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input… |
| CVE-2024-28070 | Media (6.8) | 0.45% | — | 16 mar 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input… |
| CVE-2024-28069 | Alta (7.5) | 0.57% | — | 16 mar 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A… |
| CVE-2023-22854 | Alta (7.5) | 0.60% | — | 13 feb 2023 | The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful… |
| CVE-2021-3352 | Crítica (9.1) | 1.0% | — | 13 ago 2021 | The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticated attacker to access (view and modify) user data without… |
| CVE-2020-24693 | Baja (3.3) | 0.27% | — | 18 dic 2020 | The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow a local attacker to view system information due to insufficient output sanitization. |
| CVE-2020-24692 | Alta (7.1) | 0.42% | — | 25 sept 2020 | The Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to… |
| CVE-2020-9379 | Media (6.5) | 0.92% | — | 25 feb 2020 | The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated user to access sensitive information. A successful exploit could allow… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.