CVE-2018-19275

The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mitel:cmg_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:mitel:cmg_suite:8.4:-:*:*:*:*:*:*
cpe:2.3:a:mitel:cmg_suite:8.4:sp2:*:*:*:*:*:*
cpe:2.3:a:mitel:inattend:*:*:*:*:*:*:*:*
cpe:2.3:a:mitel:inattend:2.5:-:*:*:*:*:*:*
cpe:2.3:a:mitel:inattend:2.5:sp1:*:*:*:*:*:*
cpe:2.3:a:mitel:inattend:2.5:sp2:*:*:*:*:*:*

History

21 Nov 2024, 03:57

Type Values Removed Values Added
References () https://www.mitel.com/-/media/mitel/pdf/security-advisories/security-bulletin-190002001-v10.pdf - Vendor Advisory () https://www.mitel.com/-/media/mitel/pdf/security-advisories/security-bulletin-190002001-v10.pdf - Vendor Advisory
References () https://www.mitel.com/en-gb/support/security-advisories/mitel-product-security-advisory-19-0002 - Vendor Advisory () https://www.mitel.com/en-gb/support/security-advisories/mitel-product-security-advisory-19-0002 - Vendor Advisory

Information

Published : 2019-04-02 18:29

Updated : 2024-11-21 03:57


NVD link : CVE-2018-19275

Mitre link : CVE-2018-19275

CVE.ORG link : CVE-2018-19275


JSON object : View

Products Affected

mitel

  • inattend
  • cmg_suite
CWE
CWE-1188

Insecure Default Initialization of Resource