Impact
DigitalCanion identified a path traversal flaw in the Maintenance → System Logs feature of the Mitel MiVoice Office 400 web management portal, which listens on TCP port 443. The application does not validate user‑supplied file paths properly, allowing an attacker to manipulate the requested path and traverse outside the intended logs directory. Exploitation grants the attacker the ability to read and download files that should remain inaccessible, potentially exposing sensitive system or application data and compromising confidentiality.
Affected Systems
The vulnerability affects Mitel's MiVoice Office 400 product. No specific version range is provided in the CNA data, so all deployed instances are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity; no EPSS score is available and the vulnerability is not listed in the CISA KEV dataset, suggesting that exploitation is not currently widespread. The likely attack vector requires remote access to the HTTPS management interface, but no authentication requirement is noted, implying that unauthenticated users could exploit the flaw if they can reach the portal. Because the flaw permits arbitrary file disclosure, it represents a significant confidentiality risk to any data stored outside the logs directory.
OpenCVE Enrichment