CVE-2024-36446: Mitel MiVoice Mx-One
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.
Affected products
- Mitel MiVoice Mx-One: before 7.6 (fixed in 7.6); version 7.6 only
Published 2024-08-13. Last modified 2026-06-17.