Executive brief
The Director database component of Mitel MiVoice Connect contains a code injection vulnerability due to insufficient restrictions on database data types. An authenticated attacker with internal network access can execute arbitrary code within the context of the application by providing crafted data.
Affected products
- Mitel MiVoice Connect through 19.3 (22.22.6100.0)
Timeline
- 2022-11-21: disclosed: NVD Published Date
- 2023-02-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog