{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/mitel/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MiCollab versions 10.2.x antérieures à 10.2 SP1 FP2 (10.2.1.205)","MiCollab versions 10.3.x antérieures à 10.3.0.18","MiCollab versions antérieures à 9.8 SP3 FP2 (9.8.3.203)","Openscape UC versions V10 antérieures à V10 R6 FR18","Openscape UC versions V11 antérieures à V11 R1 FR2"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","xss","mitel"],"_cs_type":"advisory","_cs_vendors":["Mitel"],"content_html":"\u003cp\u003eThe French National Agency for the Security of Information Systems (ANSSI) has published an advisory regarding multiple critical vulnerabilities discovered in Mitel's MiCollab and Openscape UC products. These security flaws allow a remote attacker to achieve arbitrary code execution (RCE) and perform indirect remote code injection, commonly known as Cross-Site Scripting (XSS). The affected versions include MiCollab versions 10.2.x prior to 10.2 SP1 FP2 (10.2.1.205), versions 10.3.x prior to 10.3.0.18, and versions prior to 9.8 SP3 FP2 (9.8.3.203). Openscape UC versions V10 prior to V10 R6 FR18 and V11 prior to V11 R1 FR2 are also impacted. These vulnerabilities pose a severe risk to organizations using the affected communications platforms, potentially leading to full system compromise or client-side attacks against users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eReconnaissance \u0026amp; Vulnerability Identification\u003c/strong\u003e: An attacker identifies publicly exposed and unpatched Mitel MiCollab or Openscape UC servers within a target organization's network perimeter.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Exploitation (RCE)\u003c/strong\u003e: The attacker crafts and sends a specially malformed HTTP request or input payload designed to trigger an arbitrary code execution vulnerability on the vulnerable server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Exploitation (XSS)\u003c/strong\u003e: Alternatively or in parallel, the attacker exploits an indirect remote code injection (XSS) vulnerability by injecting malicious client-side script into a data field or application response.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eArbitrary Code Execution\u003c/strong\u003e: The vulnerable Mitel server processes the malicious input, leading to the execution of attacker-controlled code with the privileges of the affected service or system.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eClient-Side Script Execution\u003c/strong\u003e: If the XSS vulnerability is successfully exploited, the injected script executes within the web browser of any legitimate user who subsequently accesses the compromised application.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact (RCE)\u003c/strong\u003e: Successful RCE provides the attacker with unauthorized control over the affected Mitel server, enabling actions such as deploying malware, establishing persistence, exfiltrating sensitive data, or pivoting to other systems.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact (XSS)\u003c/strong\u003e: Successful XSS allows the attacker to compromise user sessions, steal credentials, deface web content, or perform other client-side malicious actions, affecting users interacting with the vulnerable application.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of these vulnerabilities can lead to severe consequences for organizations utilizing the affected Mitel products. Remote Code Execution allows attackers to gain complete control over the compromised server, potentially leading to unauthorized access to sensitive data, system disruption, installation of backdoors, or the deployment of ransomware. Cross-Site Scripting (XSS) attacks can compromise user accounts, steal session cookies, deface websites, or launch phishing attacks against users interacting with the vulnerable application. Organizations in various sectors relying on these communication platforms for their daily operations are at risk of significant operational disruption and data breaches.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRefer to the Mitel security advisories and promptly apply the recommended patches to all affected MiCollab and Openscape UC instances.\u003c/li\u003e\n\u003cli\u003eBlock network connections to indicators of compromise from the iocs table at the network perimeter.\u003c/li\u003e\n\u003cli\u003eRegularly review web server logs for unusual requests or patterns associated with RCE or XSS exploitation attempts, including \u003ccode\u003ewebserver\u003c/code\u003e category logs for unusual \u003ccode\u003ecs-uri-stem\u003c/code\u003e or \u003ccode\u003ecs-uri-query\u003c/code\u003e values.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T11:54:26Z","date_published":"2026-07-23T11:54:26Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mitel-rce-xss/","summary":"Multiple vulnerabilities have been discovered in Mitel MiCollab and Openscape UC products, enabling a remote attacker to achieve arbitrary code execution and conduct indirect remote code injection (XSS), posing significant risks to affected organizations.","title":"Multiple Vulnerabilities in Mitel Products Allow Remote Code Execution and XSS","url":"https://feed.craftedsignal.io/briefs/2026-07-mitel-rce-xss/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MiCollab"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","network"],"_cs_type":"advisory","_cs_vendors":["Mitel"],"content_html":"\u003cp\u003eA critical remote code execution (RCE) vulnerability has been identified in Mitel MiCollab, allowing a remote, unauthenticated attacker to execute arbitrary program code on affected systems. This flaw, highlighted by CERT-Bund, presents a significant risk as it can be exploited without prior authentication, enabling complete system compromise. The vulnerability affects Mitel MiCollab, a unified communications and collaboration platform widely used in enterprise environments. Successful exploitation could lead to full control over the compromised server, allowing attackers to access sensitive data, deploy further malicious payloads such as ransomware, or pivot to other systems within the network. Organizations utilizing Mitel MiCollab should prioritize patching to mitigate the severe threat posed by this unauthenticated RCE.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker performs reconnaissance to identify an internet-exposed Mitel MiCollab server.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious payload designed to execute arbitrary code on the target system.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a specially prepared request, embedding the malicious payload, to the vulnerable Mitel MiCollab application.\u003c/li\u003e\n\u003cli\u003eThe MiCollab application processes the request, triggering the vulnerability and executing the attacker's code with the application's privileges.\u003c/li\u003e\n\u003cli\u003eThe executed code provides the attacker with an initial foothold on the server, potentially by establishing a reverse shell or creating a new user account.\u003c/li\u003e\n\u003cli\u003eThe attacker may then attempt to escalate privileges on the compromised system if the initial code execution is not at the highest privilege level.\u003c/li\u003e\n\u003cli\u003ePost-exploitation activities commence, which may include installing additional malware, exfiltrating data, or establishing persistence mechanisms.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves their final objective, such as complete system compromise, data theft, or further lateral movement within the victim's network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this critical vulnerability in Mitel MiCollab would grant an unauthenticated, remote attacker arbitrary code execution privileges on the affected server. This could lead to a full system compromise, allowing adversaries to install backdoors, exfiltrate sensitive data, deploy ransomware, or establish persistence within the victim's network. Organizations, particularly those in sectors relying heavily on unified communications, face a high risk of significant disruption, data breaches, and reputational damage if this flaw is left unaddressed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply vendor patches for Mitel MiCollab immediately to address this critical remote code execution vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T10:30:50Z","date_published":"2026-07-23T10:30:50Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mitel-micollab-rce/","summary":"A critical vulnerability in Mitel MiCollab allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full system compromise or further network penetration.","title":"Mitel MiCollab Vulnerability Allows Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-07-mitel-micollab-rce/"},{"_cs_actors":["Authenticated Attacker"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenScape"],"_cs_severities":["high"],"_cs_tags":["cross-site-scripting","vulnerability","web-application"],"_cs_type":"threat","_cs_vendors":["Mitel"],"content_html":"\u003cp\u003eA Cross-Site Scripting (XSS) vulnerability has been identified in Mitel OpenScape, allowing a remote, authenticated attacker to execute malicious scripts within the context of a victim's browser. This flaw, recently disclosed, grants the attacker the ability to bypass client-side security mechanisms and inject arbitrary code. Successful exploitation could lead to various impacts, including session hijacking, unauthorized access to sensitive user data, defacement of web content, or redirection to malicious external websites. The threat actor requires prior authentication to leverage this vulnerability, indicating that compromised user credentials or social engineering tactics to obtain them would precede the XSS attack. This vulnerability poses a significant risk to the integrity and confidentiality of user interactions within the affected Mitel OpenScape environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access (Authentication)\u003c/strong\u003e: An attacker obtains valid credentials for a Mitel OpenScape user account through various means, such as phishing, credential stuffing, or brute-force attacks.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eVulnerability Identification/Exploitation\u003c/strong\u003e: The authenticated attacker identifies a user input field, parameter, or component within the Mitel OpenScape application that is vulnerable to Cross-Site Scripting (XSS).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePayload Injection\u003c/strong\u003e: The attacker crafts and injects a malicious script payload (e.g., JavaScript code) into the vulnerable input field, often disguised within legitimate data or URL parameters.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePersistence/Delivery Mechanism\u003c/strong\u003e: The injected script is either stored persistently by the application (stored XSS), reflected back in a response to another user (reflected XSS), or delivered via a crafted link to a potential victim.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eVictim Interaction\u003c/strong\u003e: A legitimate user, typically with access to sensitive data or higher privileges, accesses the specific vulnerable application component where the malicious script resides or is reflected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eClient-Side Execution\u003c/strong\u003e: The victim's web browser renders the affected page, leading to the execution of the injected malicious JavaScript code within the security context of the Mitel OpenScape application.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact on Victim\u003c/strong\u003e: The executed script performs malicious actions, such as stealing the victim's session cookies, manipulating the displayed content, redirecting the victim to a phishing site, or initiating unauthorized actions on behalf of the victim.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Exfiltration/Further Compromise\u003c/strong\u003e: Stolen session tokens, credentials, or other sensitive data are exfiltrated to an attacker-controlled server, enabling session hijacking, unauthorized account access, or potential lateral movement within the victim's network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this XSS vulnerability by an authenticated attacker can result in significant compromise of user accounts and data within Mitel OpenScape. Victims may have their session cookies stolen, leading to session hijacking and complete takeover of their accounts without needing their passwords. This can facilitate unauthorized access to sensitive communications, contact lists, and other proprietary information managed by the platform. Attackers could also redirect users to phishing sites, perform arbitrary actions on behalf of the victim, or deface the legitimate application interface, eroding trust and potentially spreading malware. While no specific victim numbers are provided, any organization utilizing Mitel OpenScape with this unpatched vulnerability is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the latest security patches and updates released by Mitel for OpenScape immediately to address the identified XSS vulnerability.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to detect and block common XSS payloads in HTTP requests to Mitel OpenScape servers.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detect Potential Cross-Site Scripting Attempts in Web Logs\u0026quot; to your SIEM and configure it to alert on suspicious patterns in \u003ccode\u003ecs-uri-query\u003c/code\u003e and \u003ccode\u003ecs-uri-stem\u003c/code\u003e fields from web server logs.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging to capture full HTTP request details, including method, URI, query parameters, and user-agent, to aid in forensic analysis and detection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T10:26:38Z","date_published":"2026-07-23T10:26:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-mitel-openscape-xss/","summary":"A remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Mitel OpenScape, allowing the execution of malicious scripts in the victim's browser, potentially leading to session hijacking, data theft, or redirection to malicious websites.","title":"Mitel OpenScape Cross-Site Scripting Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-mitel-openscape-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Mitel","version":"https://jsonfeed.org/version/1.1"}