peter bassill · operator
$ cve CVE-2020-10211 JSON

CVE-2020-10211

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.05% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-04-17
Last modified2026-06-17

Affected (1)

VendorProduct
mitelmivoice connect

References

→ the Explorer  ·  watch your stack  ·  NVD