{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2024-28815","assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","dateUpdated":"2024-08-02T00:56:58.148Z","dateReserved":"2024-03-11T00:00:00.000Z","datePublished":"2024-03-27T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre","dateUpdated":"2024-04-30T06:45:04.676Z"},"descriptions":[{"lang":"en","value":"A vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow access to sensitive information, changes to the system configuration, or execution of arbitrary commands within the context of the system."}],"affected":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}],"references":[{"url":"https://www.mitel.com/support/security-advisories"},{"url":"https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0003"},{"url":"https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin_24-0003-001-v1.pdf"},{"url":"https://cwe.mitre.org/data/definitions/1188.html"}],"problemTypes":[{"descriptions":[{"type":"text","lang":"en","description":"n/a"}]}]},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-1188","lang":"en","description":"CWE-1188 Insecure Default Initialization of Resource"}]}],"affected":[{"vendor":"mitel","product":"inattend","cpes":["cpe:2.3:a:mitel:inattend:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"2.6_sp4","status":"affected","lessThanOrEqual":"2.7","versionType":"custom"}]},{"vendor":"mitel","product":"cmg_suite","cpes":["cpe:2.3:a:mitel:cmg_suite:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"8.5_sp4","status":"affected","lessThanOrEqual":"8.6","versionType":"custom"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":9.8,"attackVector":"NETWORK","baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-04-30T14:52:51.453912Z","id":"CVE-2024-28815","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-23T17:25:45.803Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:56:58.148Z"},"title":"CVE Program Container","references":[{"url":"https://www.mitel.com/support/security-advisories","tags":["x_transferred"]},{"url":"https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0003","tags":["x_transferred"]},{"url":"https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin_24-0003-001-v1.pdf","tags":["x_transferred"]},{"url":"https://cwe.mitre.org/data/definitions/1188.html","tags":["x_transferred"]}]}]}}