MEDIUM

CVE-2022-41223

Mitel Mivoice Connect 2022-11-22 CVSS v3.1
CVSS
6.8
KEV

Description

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

Summary dbcve.org

The Director database component of Mitel MiVoice Connect versions through 19.3 (22.22.6100.0) contains a code-injection vulnerability due to insufficient restrictions on database data types. An authenticated attacker can inject malicious code through crafted data inputs processed by the database component.

Mitigation

Apply the vendor patch (release 22.22.6100.0 or later) to remediate the data type validation weakness in the Director database component. If immediate patching is not possible, restrict database component access to trusted authenticated users only.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

10.57%
Probability of exploitation in next 30 days
95.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE