CVE-2018-19275: Mitel Cmg Suite

Critical severity, CVSS 9.8. EPSS: 4.6% chance of exploitation in the next 30 days.

The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.

Affected products

  • Mitel Cmg Suite: before 8.4 (fixed in 8.4); version 8.4 only
  • Mitel Inattend: before 2.5 (fixed in 2.5); version 2.5 only

Published 2019-04-02. Last modified 2026-06-17.