Headline
CVE-2022-41223: MiVoice Connect Code Injection Vulnerability
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
Mitel Product Security Advisory 22-0008****MiVoice Connect Code Injection Vulnerability
Advisory ID: 22-0008
Publish Date: 2022-10-12
Last Updated: 2022-10-13
Revision: 2.0
Summary
A vulnerability has been identified in the Director component of Mitel MiVoice Connect versions 19.3 (22.22.6100.0) and earlier which could allow an authenticated attacker, with internal network access, to execute arbitrary code within the context of the application.
This vulnerability was privately reported to Mitel.
Credit is given to Patrick Bennett of CrowdStrike for highlighting the issue and bringing to our attention.
Mitel is recommending customers with affected product versions apply the available remediation.
Affected Products
Product Name
Product Version
Security Bulletin
Last Updated
MiVoice Connect (Including earlier versions 14.2)
19.3 and earlier
22-0008-001
2022-10-13
Risk Assessment
The risk for this vulnerability is rated as High.
Refer to the product Security Bulletin for additional statements regarding risk.
Mitigation / Recommended Action
Customers are advised to review the product Security Bulletin and are advised to implement the available remediation steps provided.
For additional information, contact Mitel Product Support.
Related CVEs / CWEs / Advisories
CVE-2022-41223
Revision History
Version
Date
Description
1.0
2022-10-12
Initial Version
2.0
2022-10-13
Updated bulletin with revised Knowledge Base links
Related news
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The list of shortcomings is as follows - CVE-2022-47986 (CVSS score: 9.8) - IBM Aspera Faspex Code Execution Vulnerability CVE-2022-41223 (CVSS score: 6.8) - Mitel MiVoice Connect Code Injection