Mitel MiContact Center Business
cpe:2.3:a:mitel:micontact_center_business:*:*:*:*:*:*:*
- >= 10.2.0.0, <= 10.2.0.3
- >= 10.1.0.0, <= 10.1.0.5
- >= 10.0.0.0, <= 10.0.0.4
- <= 9.5.0.3
An information disclosure vulnerability exists in the legacy chat component of Mitel MiContact Center Business, affecting versions through 10.2.0.3. The vulnerability allows an unauthenticated attacker to access sensitive information by exploiting improper session data handling. This exploitation, which requires user interaction, could lead to unauthorized access to active chat rooms, allowing the attacker to read chat messages and send messages during an active session.
Successful exploitation could result in unauthorized access to active chat rooms, enabling the attacker to read chat data and send messages during an active chat session.
Users are advised to upgrade to versions 10.2.0.3, 10.1.0.5, 10.0.0.4, or 9.5.0.3, and apply the provided hotfixes. For further information, consult the Mitel Knowledge Base article SO8353 'MiContact Center Business, Security Update - CVE-2025-27827'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.