6.5
CVSSv3

CVE-2018-9102

Published: 25/04/2018 Updated: 25/05/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and previous versions, and Mitel ST 14.2, versions GA27 (19.49.5200.0) and previous versions, could allow an unauthenticated malicious user to conduct an SQL injection attack due to insufficient input validation for the signin interface. A successful exploit could allow an malicious user to extract sensitive information from the database.

Vulnerable Product Search on Vulmon Subscribe to Product

mitel st 14.2

mitel mivoice connect