← Vulnerability feed

Vulnerability record · CVE-2020-11798 · published 10 June 2020

CVE-2020-11798: Mitel MiCollab AWV directory traversal exposes server files

Mitel · Micollab Audio\

The web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 fails to properly validate access, allowing directory traversal through a crafted URL. An unauthenticated remote attacker can read files from restricted server directories, exposing sensitive information.

5.3 CVSS 3.1 Medium EPSS 49% · top 1.2% CWE-22 · Path traversal
5.3CVSS 3.1 base score, v2 5.0
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated remote file disclosure with a high EPSS score and public exploit reference, though CVSS confidentiality impact is limited.

What it is

The web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 fails to properly validate access, allowing directory traversal through a crafted URL. An unauthenticated remote attacker can read files from restricted server directories, exposing sensitive information.

Impact

An attacker gains read access to arbitrary files outside the intended web directory, which can leak configuration data, credentials or other sensitive content. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network through the web conference component via a crafted URL; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.49 (98.8th percentile), and a public Packet Storm advisory exists, so exploitation is plausible.

What to do

  • Upgrade MiCollab AWV to 8.1.2.4 or 9.1.3 (or later) per Mitel security advisory 20-0005.
  • If immediate patching is not possible, restrict network access to the AWV web conference component to trusted users or networks.
  • Review web server and application logs for traversal patterns such as ../ sequences in request paths.
  • Confirm the AWV service does not run with excessive filesystem privileges.
  • Monitor vendor advisory 20-0005 for updated guidance.

Detection

  • Search web/proxy logs for encoded or plain ../ and ..\ sequences targeting the AWV conference endpoints.
  • Alert on requests for sensitive paths such as /etc/passwd, web.config or application configuration files.
  • Baseline normal AWV URL patterns and flag anomalous file-extension or path requests.
  • Correlate outbound or internal file-read activity from the AWV host with unusual request sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11798 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19607Mitel micollab audio\ sql injection vulnerabilityA SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to ins…EPSS 1.7%9.8CVE-2019-19608Mitel micollab audio\ sql injection vulnerabilityA SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to …EPSS 1.7%9.8CVE-2019-12165Mitel micollab vulnerabilityMiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8),…EPSS 3.4%7.5CVE-2020-11797Mitel micollab audio\ vulnerabilityAn Authentication Bypass vulnerability in the Published Area of the web conferencing component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.…EPSS 1.2%6.1CVE-2019-19371Mitel micollab audio\ cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated atta…EPSS 1.0%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed

Source: NIST National Vulnerability Database (record CVE-2020-11798), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.