Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4w7-g56p-3vc4

Опубликовано: 24 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-640