
=====================================================================

                              CERT-Renater

                   Note d'Information No. 2023/VULN153

_____________________________________________________________________

DATE                : 06/04/2023

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running MiCollab versions 9.6.2.9 and
                                        earlier.

=====================================================================
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0002
_____________________________________________________________________

Mitel Product Security Advisory 23-0002
MiCollab Authentication Vulnerability

Advisory ID: 23-0002

Publish Date: 2023-04-05

Last Updated: 2023-04-05

Revision: 1.0


  Summary

An authentication vulnerability has been identified in the web
conferencing component of Mitel MiCollab which could allow an
unauthenticated attacker to download shared files. A successful
exploit could allow access to sensitive information.

Mitel is recommending customers with affected product versions
update to the latest release.

Credit is given to Ryan de Haas and Sheldon Klassen of Vumetric
for highlighting the issue and bringing to our attention.


  Affected Products

Product Name   Product Version     Security Bulletin   Last Updated
MiCollab     9.6.2.9 and earlier   23-0002-001         2023-04-05


  Risk Assessment
The risk for this vulnerability is rated as Medium. Refer to
the Product Security Bulletin for additional statements regarding risk.


  Mitigation / Recommended Action
Mitel has issued new releases of the affected software. Customers
are advised to update their software to the latest versions.


  Related CVEs / CWEs / Advisories
CVE-2023-25597

  Revision History
Version     Date           Description
1.0         2023-04-05     Initial Version


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================

