vendor:
Mitel Audio and Web Conferencing (AWC)
by:
Jan Fry of ProCheckUp Ltd
9
CVSS
CRITICAL
Unauthenticated command execution
N/A
CWE
Product Name: Mitel Audio and Web Conferencing (AWC)
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
PR10-14 Unauthenticated command execution within Mitel’s AWC (Mitel Audio and Web Conferencing)
Mitel Audio and Web Conferencing (AWC) is a simple, cost-effective and scalable audio and web conferencing solution supporting upto 200 ports. ProCheckUp has discovered that the AWC web user interface is vulnerable to an unauthenticated command execution attack. Command execution allows Unix commands to be remotely executed with the permissions associated with the web service account. No authentication is required to exploit this vulnerability.
Mitigation:
Ensure that the latest patches have been installed.