id: mitel-version-detect info: name: Mitel MiCollab Unified Communications Server (UCS) - Detect author: aushack severity: info description: | Mitel MiCollab UCS version disclosure via the /ucs/micollab/version.json endpoint. metadata: verified: true max-request: 1 shodan-query: html:"MiCollab End User Portal" tags: mitel,micollab,ucs,version,detect http: - method: GET path: - "{{BaseURL}}/ucs/micollab/version.json" matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body, "{\"version\":")' - 'contains(content_type, "text/plain")' condition: and extractors: - type: json part: body name: version group: 1 json: - ".version" # digest: 490a0046304402201550ae0539da3a597b30da3c9031e0b807351b20e08d2212fd3405712f6f53a902203e865fb85c54036ca24eace022b77546330539f8aa651fb7c33885f344b5bad5:922c64590222798bb761d5b6d8e72950