St14.2
This hub aggregates every CVE we track for St14.2, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
7
CVEs tracked
4
Critical
1
High
0
In CISA KEV
Severity distribution
CRITICAL4MEDIUM2HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 7 most recently published vulnerabilities affecting St14.2.
- CVE-2018-12901A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) a...6.1
- CVE-2018-5781A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to injec...9.8
- CVE-2018-5780A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to injec...9.8
- CVE-2018-5779A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy ...9.8
- CVE-2018-5782A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to injec...9.8
- CVE-2017-16250A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associat...5.3
- CVE-2017-16251A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST re...8.8
Product normalization is registry-driven with AI assist and human review. How it works