Description

A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit requires user interaction and could allow an attacker to execute arbitrary scripts.

INFO

Published Date :

2024-10-21T00:00:00.000Z

Last Modified :

2025-03-25T14:14:25.141Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-35314 vulnerability.

Vendors Products
Mitel
  • Micollab
  • Mivoice Business Solution Virtual Instance
  • Mivoice Business Solutions Virtual Instance

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact