CVE-2020-27154

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
18/12/2020
Last modified:
21/12/2020

Description

The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to view the user information and application data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mitel:businesscti_enterprise:*:*:*:*:*:windows:*:* 6.4.11 (excluding)
cpe:2.3:a:mitel:businesscti_enterprise:*:*:*:*:*:windows:*:* 7.0.0 (including) 7.0.3 (excluding)


References to Advisories, Solutions, and Tools