Junglewise Threat Intelligence

CVE-2022-40765: Mitel MiVoice Connect Command Injection Vulnerability

CVE-2022-40765 · Severity: critical · CVSS 6.8 · Exploited in the wild · Published 2023-02-21

Technologies: Mitel MiVoice Connect. Vendors: Mitel.

Executive brief

A command injection vulnerability in the Mitel Edge Gateway component of MiVoice Connect allows authenticated attackers with internal network access to execute arbitrary commands. The flaw exists due to insufficient restriction of URL parameters.

Affected products

  • Mitel MiVoice Connect Edge Gateway through 19.3 (22.22.6100.0)

Timeline

  • 2022-11-21: disclosed: NVD Published Date
  • 2023-02-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats