Vulnerability Details CVE-2020-10211
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-10211
-
cpe:2.3:a:mitel:mivoice_connect:-
-
cpe:2.3:a:mitel:mivoice_connect:19.1
-
cpe:2.3:a:mitel:mivoice_connect_client:214.100.1213.0