peter bassill · operator
$ cve CVE-2020-11798 JSON

CVE-2020-11798 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 48.8% (pctl 99)

Patch early

A public exploit exists.

Description

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS48.77% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2020-06-10
Last modified2026-06-17

Affected (1)

VendorProduct
mitelmicollab audio\, web \& video conferencing

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD