Record summary

CVE-2020-11798 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

micollab_audio\,_web_\&_video_conferencing

Browse Mitel / micollab_audio\,_web_\&_video_conferencing
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBMitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFIExploitDB exploitby Kahvi-0Not analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMMitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory TraversalCVSS 5.3

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.

Impact

An attacker can exploit this vulnerability to view, modify, or delete arbitrary files on the system, potentially leading to unauthorized access or data leakage.

Remediation

Apply the latest security patches or updates provided by Mitel to mitigate the vulnerability and prevent unauthorized access.

WeaknessesCWE-22
Authorsritikchaddha
Template tagscvecve2020packetstormmitelmicollablfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:mitel:micollab_audio\,_web_\&_video_conferencing:*:*:*:*:*:*:*:*
Shodan: html:"Mitel" html:"MiCollab"
Shodan: http.html:"mitel" html:"micollab"
FOFA: body="mitel" html:"micollab"

Source: ProjectDiscovery

References

4