Junglewise Threat Intelligence

CVE-2022-41223: Mitel MiVoice Connect Code Injection Vulnerability

CVE-2022-41223 · Severity: critical · CVSS 6.8 · Exploited in the wild · Published 2023-02-21

Technologies: Mitel MiVoice Connect. Vendors: Mitel.

Executive brief

The Director database component of Mitel MiVoice Connect contains a code injection vulnerability due to insufficient restrictions on database data types. An authenticated attacker with internal network access can execute arbitrary code within the context of the application by providing crafted data.

Affected products

  • Mitel MiVoice Connect through 19.3 (22.22.6100.0)

Timeline

  • 2022-11-21: disclosed: NVD Published Date
  • 2023-02-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats