CVE-2024-42514

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Oct 1, 2024
Updated: Oct 7, 2024
CWE ID 284

Summary

CVE-2024-42514 is a newly disclosed vulnerability affecting the legacy chat component of Mitel MiContact Center Business versions prior to 10.1.0.4. This issue stems from insufficient access control checks, which can enable unauthenticated attackers to gain unauthorized access during active chat sessions. Successful exploitation demands user interaction and potentially grants the attacker access to confidential information and the ability to send unapproved messages. This vulnerability poses a significant risk and necessitates immediate action from affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MiContact Center Business

Affected Vendors

  • Mitel Networks