Vulnerability record · CVE-2020-11798 · published 10 June 2020
CVE-2020-11798: Mitel MiCollab AWV directory traversal exposes server files
Mitel · Micollab Audio\
The web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 fails to properly validate access, allowing directory traversal through a crafted URL. An unauthenticated remote attacker can read files from restricted server directories, exposing sensitive information.
Description
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file disclosure with a high EPSS score and public exploit reference, though CVSS confidentiality impact is limited.
What it is
The web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 fails to properly validate access, allowing directory traversal through a crafted URL. An unauthenticated remote attacker can read files from restricted server directories, exposing sensitive information.
Impact
An attacker gains read access to arbitrary files outside the intended web directory, which can leak configuration data, credentials or other sensitive content. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network through the web conference component via a crafted URL; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.49 (98.8th percentile), and a public Packet Storm advisory exists, so exploitation is plausible.
What to do
- Upgrade MiCollab AWV to 8.1.2.4 or 9.1.3 (or later) per Mitel security advisory 20-0005.
- If immediate patching is not possible, restrict network access to the AWV web conference component to trusted users or networks.
- Review web server and application logs for traversal patterns such as ../ sequences in request paths.
- Confirm the AWV service does not run with excessive filesystem privileges.
- Monitor vendor advisory 20-0005 for updated guidance.
Detection
- Search web/proxy logs for encoded or plain ../ and ..\ sequences targeting the AWV conference endpoints.
- Alert on requests for sensitive paths such as /etc/passwd, web.config or application configuration files.
- Baseline normal AWV URL patterns and flag anomalous file-extension or path requests.
- Correlate outbound or internal file-read activity from the AWV host with unusual request sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-11798 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11798), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.