CVE-2018-19275
9.8
CRITICAL · CVSS 3.0 · EPSS 4.6% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.61% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-1188 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-04-02 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| mitel | cmg suite |
| mitel | inattend |
References
- https://www.mitel.com/-/media/mitel/pdf/security-advisories/security-bulletin-190002001-v10.pdf
- https://www.mitel.com/en-gb/support/security-advisories/mitel-product-security-advisory-19-0002
- https://www.mitel.com/-/media/mitel/pdf/security-advisories/security-bulletin-190002001-v10.pdf
- https://www.mitel.com/en-gb/support/security-advisories/mitel-product-security-advisory-19-0002
→ the Explorer · watch your stack · NVD