CVE-2023-25597: Mitel MiCollab
Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due to improper authentication control. A successful exploit could allow access to sensitive information.
Affected products
- Mitel MiCollab: before 9.7 (fixed in 9.7)
Published 2023-04-14. Last modified 2026-06-17.