CVE-2024-42514

HIGH

Mitel MiContact Center Business <10.1.0.4 - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive information and send unauthorized messages during an active chat session.

Scores

CVSS v3 8.1
EPSS 0.0042
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
mitel/micontact_center_business < 10.1.0.4
Published Oct 01, 2024
Tracked Since Feb 18, 2026