mitel mivoice-connect CVE-2022-40765 is a vulnerability in Mitel Mivoice Connect
Published on November 22, 2022

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

Vendor Advisory Vendor Advisory NVD

Known Exploited Vulnerability

This Mitel MiVoice Connect Command Injection Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

The following remediation steps are recommended / required by March 14, 2023: Apply updates per vendor instructions.

Vulnerability Analysis

What is a Command Injection Vulnerability?

The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CVE-2022-40765 has been classified to as a Command Injection vulnerability or weakness.


Products Associated with CVE-2022-40765

You can be notified by stack.watch whenever vulnerabilities like CVE-2022-40765 are published in these products:

 

What versions of Mivoice Connect are vulnerable to CVE-2022-40765?