Junglewise Threat Intelligence

CVE-2022-29499: Mitel MiVoice Connect Data Validation Vulnerability

CVE-2022-29499 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-06-27

Technologies: Mitel MiVoice Connect. Vendors: Mitel.

Executive brief

The Service Appliance component in Mitel MiVoice Connect (SA 100, SA 400, and Virtual SA) contains a data validation vulnerability. This flaw allows a remote, unauthenticated attacker to execute arbitrary code on the affected device.

Affected products

  • Mitel MiVoice Connect Service Appliance SA 100 through 19.2 SP3
  • Mitel MiVoice Connect Service Appliance SA 400 through 19.2 SP3
  • Mitel MiVoice Connect Virtual Service Appliance through 19.2 SP3

Timeline

  • 2022-04-25: disclosed: NVD Published Date
  • 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-27: exploited: Reported as exploited in the wild

Related threats