Executive brief
A command injection vulnerability in the Mitel Edge Gateway component of MiVoice Connect allows authenticated attackers with internal network access to execute arbitrary commands. The flaw exists due to insufficient restriction of URL parameters.
Affected products
- Mitel MiVoice Connect Edge Gateway through 19.3 (22.22.6100.0)
Timeline
- 2022-11-21: disclosed: NVD Published Date
- 2023-02-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog