Lucene search

K
cveMitreCVE-2020-24594
HistorySep 25, 2020 - 4:23 a.m.

CVE-2020-24594

2020-09-2504:23:04
CWE-79
mitre
web.nvd.nist.gov
37
mitel
micloud
management portal
6.1 sp5
unauthenticated
attacker
execute
arbitrary
scripts
xss

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.003

Percentile

69.6%

Mitel MiCloud Management Portal before 6.1 SP5 could allow an unauthenticated attacker to execute arbitrary scripts due to insufficient input validation, aka XSS. A successful exploit could allow an attacker to gain access to a user session.

Affected configurations

Nvd
Node
mitelmicloud_management_portalRange6.0
OR
mitelmicloud_management_portalMatch6.1-
OR
mitelmicloud_management_portalMatch6.1sp4
VendorProductVersionCPE
mitelmicloud_management_portal*cpe:2.3:a:mitel:micloud_management_portal:*:*:*:*:*:*:*:*
mitelmicloud_management_portal6.1cpe:2.3:a:mitel:micloud_management_portal:6.1:-:*:*:*:*:*:*
mitelmicloud_management_portal6.1cpe:2.3:a:mitel:micloud_management_portal:6.1:sp4:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.003

Percentile

69.6%

Related for CVE-2020-24594