CVE-2024-42514
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-42514 is a newly disclosed vulnerability affecting the legacy chat component of Mitel MiContact Center Business versions prior to 10.1.0.4. This issue stems from insufficient access control checks, which can enable unauthenticated attackers to gain unauthorized access during active chat sessions. Successful exploitation demands user interaction and potentially grants the attacker access to confidential information and the ability to send unapproved messages. This vulnerability poses a significant risk and necessitates immediate action from affected organizations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- MiContact Center Business
Affected Vendors
- Mitel Networks