CVE-2022-41326
Last modified
CVE-2022-41326 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitel | Micollab | <= 9.6.0.105 |
References
- https://www.mitel.com/support/security-advisoriesVendor Advisory
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0009Mitigation, Vendor Advisory
- https://www.mitel.com/support/security-advisoriesVendor Advisory
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0009Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-41326?
How severe is CVE-2022-41326?
How do I fix CVE-2022-41326?
Are you affected by CVE-2022-41326?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
