SECURITY ADVISORIES

Mitel Product Security Advisories are published for moderate and high-risk security issues. Each advisory provides information on the status of investigation and provides additional information on products confirmed to be affected and recommended action to be taken by customers. Advisories are posted in reverse chronological order.

This information is provided on an "as is" basis and does not grant or imply any guarantees or warranties, including the warranties of merchantability or fitness for a particular use. Mitel does not guarantee that any of the information is accurate or up to date. By using the information, you acknowledge and agree that your use of the information, or the documents or materials linked to this information, is at your own risk. In addition, Mitel’s provision of this information shall not and does not affect the terms or conditions of any agreement with Mitel. Mitel reserves the right to change or update this information without notice at any time.

Click here for a more comprehensive details on Mitel’s Product Security Policy ›

Stay one step ahead.

Get weekly notifications of the latest security advisories delivered straight to your inbox!

Sign-up
Supports
Advisory ID CVE# Severity Publish Date Last Updated Sort ascending
MiCollab SQL Injection Vulnerability 24-0014 CVE-2024-35286 critical
OpenScape UC Application Exposure of Sensitive Information Vulnerability  OBSO-2405-01 medium
Mitel 6800 Series, 6900 Series and 6900w Series SIP Phones, including 6970 Conference Unit Argument Injection Vulnerability 24-0009 CVE-2024-31966 medium
Mitel 6800 Series, 6900 Series and 6900w Series SIP Phones, including 6970 Conference Unit Buffer Overflow Vulnerability 24-0006 CVE-2024-31963 medium
Mitel 6800 Series, 6900 Series and 6900w Series SIP Phones, including 6970 Conference Unit Authentication Bypass Vulnerability 24-0007 CVE-2024-31964 medium
Mitel 6800 Series, 6900 Series and 6900w Series SIP Phones, including 6970 Conference Unit Path Traversal Vulnerability 24-0008 CVE-2024-31965 medium
Mitel 6800 Series, 6900 Series and 6900w Series SIP Phones, including 6970 Conference Unit Information Disclosure Vulnerability 24-0010 CVE-2024-31967 medium
MiCollab SQL Injection vulnerability 24-0004 CVE-2024-30157, CVE-2024-30158 high
MiCollab Stored Cross-Site Scripting (XSS) Vulnerability 24-0005 CVE-2024-30159, CVE-2024-30160 high
OpenScape Desk Phones CP Credentials disclosure vulnerability OBSO-2404-01 CVE-2024-28065, CVE-2024-28066 low
Mitel InAttend and Mitel CMG Improper Configuration Vulnerability 24-0003 CVE-2024-28815 critical
MiContact Center Business Information Disclosure Vulnerability 24-0001 CVE-2024-28069 high
MiContact Center Business Reflected Cross Site Scripting Vulnerability 24-0002 CVE-2024-28070 high
Security Advisory Report - OBSO-2305-02 OBSO-2305-02 CVE-2023-40262, CVE-2023-40263, CVE-2023-40264 critical
Security Advisory Report - OBSO-2305-03 OBSO-2305-03 CVE-2023-40265, CVE-2023-40266 high to medium
OpenScape Business V3 Command injection vulnerability OBSO-2401-03 high
Apache ActiveMQ OpenWire Protocol Class Type Manipulation Arbitrary Code Execution Vulnerability (CVE-2023-46604)  OBSO-2401-02 CVE-2023-46604 critical to high
Security Advisory Report - OBSO-2312-01 OBSO-2312-01 CVE-2025-XXXXX high to medium
Security Advisory Report - OBSO-2310-02 OBSO-2310-02 CVE-2023-4863, CVE-2023-5129 high to medium
Security Advisory Report - OBSO-2310-01 OBSO-2310-01 CVE-2023-6269 critical
Security Advisory Report - OBSO-2207-01 OBSO-2207-01 CVE-2022-0778 high to medium
Security Advisory Report - OBSO-2306-01 OBSO-2306-01 CVE-2023-45349, CVE-2023-45350, CVE-2023-45351 high
Security Advisory Report - OBSO-2308-02 OBSO-2308-02 CVE-2023-45355, CVE-2023-45356 high
Security Advisory Report - OBSO-2306-02 OBSO-2306-02 CVE-2023-45352, CVE-2023-45353, CVE-2023-45354 high
Security Advisory Report - OBSO-2210-01 OBSO-2210-01 CVE-2022-42889 medium
Mitel Product Security Advisory 23-0014 23-0014 CVE-2023-39285 medium
Mitel Product Security Advisory 23-0015 23-0015 CVE-2023-39286 medium
Mitel Product Security Advisory 23-0010 23-0010 CVE-2023-39287 medium
Mitel Product Security Advisory 23-0011 23-0011 CVE-2023-39288, CVE-2023-39289 medium
Mitel Product Security Advisory 23-0012 23-0012 CVE-2023-39290 medium
Stay one step ahead

Get notifications of the latest security advisories sent right to your inbox every week!