Executive brief
The Service Appliance component in Mitel MiVoice Connect (SA 100, SA 400, and Virtual SA) contains a data validation vulnerability. This flaw allows a remote, unauthenticated attacker to execute arbitrary code on the affected device.
Affected products
- Mitel MiVoice Connect Service Appliance SA 100 through 19.2 SP3
- Mitel MiVoice Connect Service Appliance SA 400 through 19.2 SP3
- Mitel MiVoice Connect Virtual Service Appliance through 19.2 SP3
Timeline
- 2022-04-25: disclosed: NVD Published Date
- 2022-06-27: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-06-27: exploited: Reported as exploited in the wild