CVE-2022-40765
Mitel MiVoice Connect Command Injection Vulnerability
Severity Score
6.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
Una vulnerabilidad en el componente Edge Gateway de Mitel MiVoice Connect hasta la versión 19.3 (22.22.6100.0) podría permitir que un atacante autenticado con acceso a la red interna lleve a cabo un ataque de inyección de comandos, debido a una restricción insuficiente de los parámetros de URL.
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-09-18 CVE Reserved
- 2022-11-22 CVE Published
- 2023-02-21 Exploited in Wild
- 2023-03-14 KEV Due Date
- 2024-06-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mitel.com/support/security-advisories | 2022-11-26 | |
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0007 | 2022-11-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitel Search vendor "Mitel" | Mivoice Connect Search vendor "Mitel" for product "Mivoice Connect" | < 19.3 Search vendor "Mitel" for product "Mivoice Connect" and version " < 19.3" | - |
Affected
| ||||||
Mitel Search vendor "Mitel" | Mivoice Connect Search vendor "Mitel" for product "Mivoice Connect" | 19.3 Search vendor "Mitel" for product "Mivoice Connect" and version "19.3" | - |
Affected
|