CVE-2020-27154: Mitel Businesscti Enterprise

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

The chat window of Mitel BusinessCTI Enterprise (MBC-E) Client for Windows before 6.4.11 and 7.x before 7.0.3 could allow an attacker to gain access to user information by sending arbitrary code, due to improper input validation. A successful exploit could allow an attacker to view the user information and application data.

Affected products

  • Mitel Businesscti Enterprise: before 6.4.11 (fixed in 6.4.11); from 7.0.0, before 7.0.3 (fixed in 7.0.3)

Published 2020-12-18. Last modified 2026-06-17.