CVE-2023-39289

HIGH

Mitel MiVoice Connect <= 9.6.2208.101 - Unauthenticated Account Enumeration via Connect Mobility Router

Title source: llm
STIX 2.1

Description

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information.

Scores

CVSS v3 7.5
EPSS 0.0049
EPSS Percentile 38.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
mitel/mivoice_connect < 9.6.2208.101
Published Aug 25, 2023
Tracked Since Feb 18, 2026