Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-16251

A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an attacker to execute arbitrary code within the context of the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2017-16251
  • Mitel » St14.2 » Version: N/A
    cpe:2.3:a:mitel:st14.2:-
  • Mitel » St14.2 » Version: ga28
    cpe:2.3:a:mitel:st14.2:ga28


Contact Us

Shodan ® - All rights reserved