ZeroHour

Vulnerabilities

131 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-67823
A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticat

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

NVD description · AI analysis pending
8.2<1%
  • mitel cx
  • mitel micontact center business
CVE-2025-67822
A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attac

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized access to user or admin accounts in the system.

NVD description · AI analysis pending
9.4<1%
  • mitel mivoice mx-one
CVE-2025-52914
A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduc

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary SQL database commands.

NVD description · AI analysis pending
8.8<1%
  • mitel micollab
CVE-2024-55550
Authenticated Path Traversal in Mitel MiCollab Enables Local File Reading

Mitel MiCollab contains a path traversal vulnerability (CWE-22) caused by insufficient input sanitization of file-path input. It is triggered when an authenticated user with administrative privileges submits crafted paths that escape the intended directory, allowing the attacker to read local files on the MiCollab server. On its own the flaw requires admin credentials, but it can be chained with CVE-2024-41713, an unauthenticated remote arbitrary file-read flaw in the same product, enabling remote attackers to read files without valid credentials. Any organization running Mitel MiCollab is affected; the available data does not specify affected or fixed version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, although no public proof-of-concept is known.

Do: Apply Mitel's updates or mitigations per the vendor advisory immediately, prioritizing internet-facing MiCollab servers, and address the chained CVE-2024-41713 issue in the same maintenance cycle; where mitigations are unavailable, restrict or discontinue use per CISA KEV guidance. Check the Mitel advisory for exact fixed versions (not provided here), limit administrative access to trusted users, and review server logs for evidence of arbitrary file reads or follow-on ransomware activity.

2.738% KEV ransomware
  • Mitel MiCollab
moderatethousands of internet-exposed MiCollab servers (roughly 1k-10k instances)
CVE-2024-41713
Unauthenticated Path Traversal in Mitel MiCollab NuPoint Unified Messaging

CVE-2024-41713 is a path traversal vulnerability (CWE-22) in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201), caused by insufficient input validation. An unauthenticated remote attacker can send crafted requests that traverse the file system without needing credentials or user interaction. A successful exploit grants unauthorized access allowing the attacker to view, corrupt, or delete users' data and system configurations, and reporting indicates exposure to unauthorized file and administrative access. Any organization running an affected MiCollab version, particularly with the NPM component reachable from untrusted networks, is at risk. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, and EPSS places it in the top percentile with a 98.1% probability of exploitation within 30 days.

Do: Upgrade MiCollab to a release later than 9.8 SP1 FP2 (9.8.1.201) per Mitel's advisory; if patching is not immediately possible, apply the vendor's mitigations or restrict/discontinue use of the NPM component, especially where it is internet-facing, as required by the CISA KEV entry. Given known ransomware use and reported admin-access abuse, hunt for signs of exploitation on exposed MiCollab servers (unexpected file changes, configuration tampering, and follow-on lateral movement).

9.1
group max
98% KEV ransomware
  • Mitel MiCollab (NuPoint Unified Messaging component) through 9.8 SP1 FP2 (9.8.1.201)
largeon the order of tens of thousands of enterprise deployments, with thousands of MiCollab instances likely internet-exposed
CVE-2024-42514
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthori

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.

NVD description · AI analysis pending
8.1<1%
  • mitel micontact center business
CVE-2024-36446
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due

The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.

NVD description · AI analysis pending
8.8<1%
  • mitel mivoice mx-one
CVE-2024-41710
Argument Injection RCE in Mitel 6800/6900/6900w Series SIP Phones

CVE-2024-41710 is an argument injection vulnerability (CWE-88) affecting Mitel 6800 Series, 6900 Series, and 6900w Series SIP phones, including the 6970 Conference Unit, caused by insufficient sanitization of parameters processed during the device's boot process. An attacker who can supply crafted arguments to the boot process can inject and execute arbitrary commands within the context of the phone's system. Organizations deploying these enterprise desk phones are affected; the available data does not specify affected or fixed firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-12, confirming exploitation in the wild, though no public proof-of-concept is known and any ransomware association is unconfirmed. EPSS assigns a 41.6% probability of exploitation within the next 30 days (99th percentile), so remediation should be treated as urgent.

Do: Update affected 6800/6900/6900w series phones to the fixed firmware per Mitel's security advisory and reboot the phones so they boot with patched firmware, since the flaw is in the boot process; if fixed firmware is unavailable, apply Mitel's mitigations or discontinue use per the CISA KEV required action. Check whether phone management or provisioning interfaces are reachable from untrusted networks and restrict that access. Given KEV-listed exploitation and a 99th-percentile EPSS score, prioritize remediation, and note federal agencies are required to act under the KEV deadline.

7.242% KEV PoC
  • Mitel 6800 Series SIP Phones
  • Mitel 6900 Series SIP Phones
  • Mitel 6900w Series SIP Phones
  • +1 more
largeon the order of 100,000+ deployed handsets globally (enterprise VoIP installed base estimate; internet-exposed subset likely smaller)
CVE-2024-37569
+1 in the same advisory: …37570
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices.

An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is subsequently written to disk. During boot, the hostname parameter is executed as part of a series of shell commands. Attackers can achieve remote code execution in the root context by placing shell metacharacters in the hostname parameter.

NVD description · AI analysis pending
8.83% PoC ×2
  • mitel 6869i sip firmware
CVE-2024-35283
+1 in the same advisory: …35284
A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-si

A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation.

NVD description · AI analysis pending
6.1
group max
<1%
  • mitel micontact center business
CVE-2024-28066
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

NVD description · AI analysis pending
8.8<1% PoC
  • mitel 6940w firmware
  • mitel 6930w firmware
  • mitel 6920w firmware
  • +1 more
CVE-2024-28069
+1 in the same advisory: …28070
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an informati

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive information and potentially conduct unauthorized actions within the vulnerable component.

NVD description · AI analysis pending
7.5
group max
<1%
  • mitel micontact center business
CVE-2023-40266
+1 in the same advisory: …40265
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911.

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

NVD description · AI analysis pending
9.8
group max
<1%
  • mitel unify openscape xpressions webassistant
CVE-2023-39286
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cros

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.

NVD description · AI analysis pending
4.3<1%
  • mitel connect mobility router
CVE-2023-39285
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cros

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.

NVD description · AI analysis pending
4.3<1%
  • mitel mivoice connect
CVE-2023-39289
+4 in the same advisory: …39288 …39287 …39290 …39291
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an acc

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information.

NVD description · AI analysis pending
7.5
group max
<1%
  • mitel mivoice connect
CVE-2023-39293
+1 in the same advisory: …39292
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute a

A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.

NVD description · AI analysis pending
9.82%
  • mitel mivoice office 400
  • mitel mivoice office 400 smb controller firmware
CVE-2023-32748
The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to

The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

NVD description · AI analysis pending
9.8<1%
  • mitel mivoice connect
CVE-2023-31457
A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attack

A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

NVD description · AI analysis pending
9.8
group max
<1%
  • mitel mivoice connect
CVE-2023-25597
A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a craf

A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit could allow access to sensitive information.

NVD description · AI analysis pending
5.9<1%
  • mitel micollab
CVE-2023-22854
The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due

The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information.

NVD description · AI analysis pending
7.5<1%
  • mitel micontact center business