MITEL has issued two critical security advisories regarding vulnerabilities in their products. The first advisory details a command injection vulnerability in MiCollab rated CVSS 9.8, which allows unauthenticated attackers to execute arbitrary commands remotely. The second advisory discusses a reflected cross-site scripting (XSS) vulnerability in OpenScape UC with a CVSS rating of 8.0, requiring prior user authentication. Both vulnerabilities currently lack CVE identifiers.
Affected versions of MiCollab range from 10.0 to 10.2 SP1 FP2, while OpenScape UC versions from V11 R0 to V11 R1 FR1 HF1 are impacted. Mitigation includes upgrading to secure versions or applying patches provided by Mitel.