Impact
A path traversal flaw exists in Mitel MiVoice Office 400 that allows an attacker to view or download arbitrary system files through the web portal by navigating to Administration → View Logs. The vulnerability permits reading sensitive configuration files or binaries, resulting in confidentiality loss if accessed by an unauthorized user.
Affected Systems
Mitel MiVoice Office 400 is affected; no specific versions are listed, so any installation of this product is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity exposure. EPSS data is not available, and the vulnerability is not in the CISA KEV catalog. The flaw is exploitable over the HTTPS portal, likely requiring authenticated access to the Administration view; a victim must be able to log into the web interface. An attacker with administrative or privileged access to the portal can traverse directories and retrieve system files, potentially leading to further exploitation. The high score combined with remote availability makes this a significant risk for affected deployments.
OpenCVE Enrichment