CRITICAL

CVE-2022-29499

Mitel Mivoice Connect 2022-04-26 CVSS v3.1
CVSS
9.8
KEV

Description

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

Summary dbcve.org

Remote code execution vulnerability in the Mitel MiVoice Connect Service Appliance component (SA 100, SA 400, and Virtual SA) through version 19.2 SP3, caused by incorrect data validation that allows unauthenticated network attackers to execute arbitrary code. The critical CVSS 9.8 score reflects remote, low-complexity exploitation without authentication against telephony infrastructure appliances.

Mitigation

Upgrade the Mitel MiVoice Connect Service Appliance to a version newer than 19.2 SP3 that incorporates the vendor's data-validation fix, applying it to all SA 100, SA 400, and Virtual SA instances, and restrict network access to the appliance management interface as a compensating control until the update is applied.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

54.32%
Probability of exploitation in next 30 days
99th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE