Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mitel

First CVE: Feb 28, 2004Active for: 22 yearsTotal CVEs: 135
62.2
VTI Score
TOP TARGET

Mitel's vulnerability profile spans a well-represented portfolio of unified communications, contact center, and conferencing products serving enterprise deployments, presenting a significant attack surface across collaboration infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have a meaningful tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the internet-facing and authentication-sensitive nature of these systems. The exposure recurs across products such as MiCollab, MiVoice Connect, and MiContact Center Business through weakness classes including cross-site scripting, SQL injection, improper input validation, and code injection—characteristic of web-centric and database-integrated platforms where input handling and output encoding are persistently challenging. Defenders should prioritize patches for internet-reachable collaboration and contact center instances and treat this vendor's advisories as high-priority for systems handling sensitive communications. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
135
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
5.9%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Mitel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2004
22 years ago
Most Recent CVE
Jan 15, 2026
190 days ago

Products(128 total)

Top CVEs

Signals from CVEs in this vendor scope (135 CVEs).

135 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-0160HIGH
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform
Apr 7, 20147.599YESYES
CVE-2024-41713CRITICAL
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path travers
Oct 21, 20249.197YESYES
CVE-2022-26143CRITICAL
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause
Mar 10, 20229.897YESYES
CVE-2022-29499CRITICAL
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 4
Apr 26, 20229.890YESNO
CVE-2024-41710HIGH
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated
Aug 12, 20247.283YESNO
CVE-2024-55550LOW
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successfu
Dec 10, 20242.779YESYES
CVE-2024-35286CRITICAL
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization
Oct 21, 20249.877NOYES
CVE-2022-41223MEDIUM
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insu
Nov 22, 20226.867YESNO
CVE-2022-40765MEDIUM
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a c
Nov 22, 20226.866YESNO
CVE-2018-3639MEDIUM
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori
May 22, 20185.565NOYES
View all 135 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products135 CVEs
44%
27%
26%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (4.4%)
Network117 (86.7%)
Unknown3 (2.2%)
Physical2 (1.5%)
Adjacent Network7 (5.2%)
Attack Complexity
Low124 (91.9%)
High8 (5.9%)
Unknown3 (2.2%)
User Interaction
None99 (73.3%)
Unknown3 (2.2%)
Required33 (24.4%)
Privileges Required
Low23 (17.0%)
High19 (14.1%)
None90 (66.7%)
Unknown3 (2.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (135 CVEs).

CISA KEV
8 CVEs
5.9% of CVEs· 100th percentile
Metasploit
1 CVE
0.7% of CVEs· 97th percentile
Nuclei
7 CVEs
5.2% of CVEs· 96th percentile
ExploitDB
8 CVEs
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mitel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mitel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mitel's Products

View all 4 CNAs →

Top CWEs