MEDIUM
CVE-2022-40765
CVSS
6.8
KEV
Description
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
Summary dbcve.org
A command-injection vulnerability exists in the Edge Gateway component of Mitel MiVoice Connect (versions through 19.3/22.22.6100.0). Authenticated attackers with internal network access can inject arbitrary commands through URL parameters that are not properly validated or restricted.
Mitigation
Implement strict input validation and sanitization on all URL parameters within the Edge Gateway component. Restrict the authentication requirements and network access to minimize the attack surface.
Weakness (CWE)
CWE-77
Command Injection
EPSS Score
10.57%
Probability of exploitation in next 30 days
95.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.