← Vulnerability feed

Vulnerability record · CVE-2019-12165 · published 29 May 2019

CVE-2019-12165: Mitel micollab vulnerability

Mitel · Micollab

MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability. Successful exploit of this vulnerability could allow an attacker to execute arbitrary system commands.

9.8 CVSS 3.1 Critical EPSS 3.4% · top 11.6%
9.8CVSS 3.1 base score, v2 10.0
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability. Successful exploit of this vulnerability could allow an attacker to execute arbitrary system commands.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12165 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26143Mitel MiCollab TP-240 missing authentication enables DDoS and data exposureThe TP-240 (tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 lacks authentication for a critical fun…KEVEPSS 87%analysed9.1CVE-2024-41713Mitel MiCollab NuPoint path traversal allows unauthenticated file accessMitel MiCollab's NuPoint Unified Messaging component fails to validate input, allowing a path traversal attack through version 9.8 SP1 FP2 (9.8.1.201…KEVEPSS 98%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed2.7CVE-2024-55550Mitel MiCollab path traversal allows admin local file readMitel MiCollab through 9.8 SP2 has a path traversal flaw (CWE-22) caused by insufficient input sanitization. An authenticated attacker with administr…KEVEPSS 38%analysed9.8CVE-2024-35285Mitel micollab command injection vulnerabilityA vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attac…EPSS 1.3%9.8CVE-2024-35286Mitel MiCollab NuPoint Messenger unauthenticated SQL injectionNuPoint Messenger in Mitel MiCollab through 9.8.0.33 fails to sanitize user input, allowing SQL injection. An unauthenticated attacker can reach the …EPSS 66%analysed9.8CVE-2024-35314Mitel micollab code injection vulnerabilityA vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could …EPSS 1.8%9.8CVE-2022-41326Mitel micollab missing authorization vulnerabilityThe web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2019-12165), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.