Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Mitel Patches Critical Flaw in Enterprise Communication Platform

Posted on July 25, 2025July 25, 2025 By CWS

Mitel this week introduced patches for a critical-severity vulnerability within the MiVoice MX-ONE enterprise communication platform that would permit attackers to realize administrator rights.

No CVE identifier has been assigned to the flaw, however Mitel says it has a CVSS score of 9.4, because it might permit distant, unauthenticated attackers to entry person or admin accounts on the system.

Mitel describes the safety defect as an authentication bypass difficulty that exists as a result of entry controls should not correctly applied.

“An authentication bypass vulnerability has been recognized within the Provisioning Supervisor element of Mitel MiVoice MX-ONE, which if efficiently exploited might permit an unauthenticated attacker to conduct an authentication bypass assault because of improper entry management,” the corporate says.

The bug impacts MiVoice MX-ONE variations 7.3 (7.3.0.0.50) to 7.8 SP1 (7.8.1.0.14), and was addressed with the discharge of MXO-15711_78SP0 and MXO-15711_78SP1 for MX-ONE variations 7.8 and seven.8 SP1, respectively.

“For MiVoice MX-ONE model 7.3 and above, please submit a patch request to your approved service companion. Patches are made obtainable at Mitel’s discretion,” the corporate notes.

The seller urges clients to use the patches instantly, noting that the MX-ONE companies shouldn’t be uncovered to the web, and that proscribing entry to the Provisioning Supervisor service or disabling it ought to mitigate the chance.

Cybersecurity agency Arctic Wolf says it has not noticed the vulnerability being exploited within the wild, and no proof-of-concept (PoC) exploit concentrating on it seems to exist publicly.Commercial. Scroll to proceed studying.

Nevertheless, customers ought to apply the obtainable fixes as quickly as attainable, on condition that risk actors have focused Mitel vulnerabilities for which patches have been launched.

In January, the Aquabot botnet was seen exploiting a vulnerability in Mitel telephones that was addressed in July 2024. Two weeks later, the US cybersecurity company CISA added two Mitel MiCollab flaws to the KEV catalog.

Associated: Crucial Vulnerability Exposes Many Mitel MiCollab Situations to Distant Hacking

Associated: SonicWall Patches Crucial SMA 100 Vulnerability, Warns of Latest Malware Assault

Associated: Airoha Chip Vulnerabilities Expose Headphones to Takeover

Associated: New Vulnerabilities Expose Thousands and thousands of Brother Printers to Hacking

Security Week News Tags:Communication, Critical, Enterprise, Flaw, Mitel, Patches, Platform

Post navigation

Previous Post: Sophisticated Koske Linux Malware Developed With AI Aid
Next Post: Staying Ahead Of The Curve With A Temporary Email Address

Related Posts

Russian Hackers Bypass Gmail MFA with App Specific Password Ruse Security Week News
Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack Security Week News
In Other News: Cloudflare Outage, Cracked.io Users Identified, Victoria’s Secret Cyberattack Cost Security Week News
Gerrit Misconfiguration Exposed Google Projects to Malicious Code Injection Security Week News
Valarian Bags $20M Seed Capital for ‘Isolation-First’ Infrastructure Tech Security Week News
New ClickFix Malware Variant ‘LightPerlGirl’ Targets Users in Stealthy Hack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VOIP-Based Botnet Attacking Routers Configured With Default Password
  • How to Report a Stolen Identity
  • Web-to-App Funnels: Pros And Cons
  • Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide
  • 10 Best API Monitoring Tools in 2025

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VOIP-Based Botnet Attacking Routers Configured With Default Password
  • How to Report a Stolen Identity
  • Web-to-App Funnels: Pros And Cons
  • Microsoft 365 Admin Center Outage Blocks Access for Admins Worldwide
  • 10 Best API Monitoring Tools in 2025

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News