LOGIN PORTAL
Americas
Europe
Oceania
Business Phone Systems
Collaboration
Contact Center
Phones & Accessories
Apps & Developers
Your Business Need
Your Industry
Your Business Size
Our Services
Our Products
Blog
About Mitel
Careers
Customer Success
Resource Center
Location: United Kingdom
Advisory ID: 22-0007
Publish Date: 2022-10-12
Last Updated: 2022-10-13
Revision: 2.0
A vulnerability has been identified in the Mitel Edge Gateway component of MiVoice Connect versions 19.3 (22.22.6100.0) and earlier which could allow an authenticated attacker, with internal network access, to execute arbitrary commands within the context of the system.
This vulnerability was privately reported to Mitel.
Credit is given to Patrick Bennett and Brian Pitchford of CrowdStrike for highlighting the issue and bringing to our attention.
Mitel is recommending customers with affected product versions apply the available remediation.
Product Name | Product Version | Security Bulletin | Last Updated |
---|---|---|---|
MiVoice Connect | 19.3 and earlier |
22-0007-001 | 2022-10-13 |
Customers are advised to review the product Security Bulletin and are advised to update their software to the latest version.
For additional information, contact Mitel Product Support.
Version | Date | Description |
---|---|---|
1.0 | 2022-10-12 | Initial Version |
2.0 | 2022-10-13 | Updated bulletin with revised Knowledge Base links |