Advisory ID: 20-0005 Publish Date: 2020-04-30 Last Updated: 2020-04-30 Revision: 1.0 Summary: - Directory Traversal vulnerability affecting Mitel MiCollab AWV via the web conference component (CVE-2020-11798) - Authentication Bypass vulnerability affecting Mitel MiCollab AWV versions 8.1.2.4 and 9.1.3 in the Published Area of the web conferencing component (CVE-2020-11797) Affected Products: - MiCollab AWV: Versions 8.1.2 and earlier, Security Bulletin: 20-0005-01, Last Updated: 2020-05-01 - MiCollab AWV: Versions 9.1.2 and earlier, Security Bulletin: 20-0005-02, Last Updated: 2020-05-01 Risk Assessment: Medium to High Mitigation / Recommended Action: Update to the latest release, review the product Security Bulletin and contact Product Support if needed Related CVEs / CWEs / Advisories: - CVE-2020-11798 - CVE-2020-11797