Mitel's vulnerability profile spans a well-represented portfolio of unified communications, contact center, and conferencing products serving enterprise deployments, presenting a significant attack surface across collaboration infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a meaningful tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the internet-facing and authentication-sensitive nature of these systems. The exposure recurs across products such as MiCollab, MiVoice Connect, and MiContact Center Business through weakness classes including cross-site scripting, SQL injection, improper input validation, and code injection—characteristic of web-centric and database-integrated platforms where input handling and output encoding are persistently challenging. Defenders should prioritize patches for internet-reachable collaboration and contact center instances and treat this vendor's advisories as high-priority for systems handling sensitive communications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mitel over time
Signals from CVEs in this vendor scope (135 CVEs).
135 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
CVE-2024-41713CRITICAL A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path travers | Oct 21, 2024 | 9.1 | 97 | YES | YES |
CVE-2022-26143CRITICAL The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause | Mar 10, 2022 | 9.8 | 97 | YES | YES |
CVE-2022-29499CRITICAL The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 4 | Apr 26, 2022 | 9.8 | 90 | YES | NO |
CVE-2024-41710HIGH A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated | Aug 12, 2024 | 7.2 | 83 | YES | NO |
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successfu | Dec 10, 2024 | 2.7 | 79 | YES | YES |
CVE-2024-35286CRITICAL A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization | Oct 21, 2024 | 9.8 | 77 | NO | YES |
CVE-2022-41223MEDIUM The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insu | Nov 22, 2022 | 6.8 | 67 | YES | NO |
CVE-2022-40765MEDIUM A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a c | Nov 22, 2022 | 6.8 | 66 | YES | NO |
CVE-2018-3639MEDIUM Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori | May 22, 2018 | 5.5 | 65 | NO | YES |
Signals from CVEs in this vendor scope (135 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mitel.
Media articles that mention a CVE ID that affects a product developed by Mitel — matched by CVE ID, not by vendor name.