Mitel Product Security Advisory 22 0007

Mitel Product Security Advisory 22-0007

MiVoice Connect Command Injection Vulnerability

Advisory ID: 22-0007

Publish Date: 2022-10-12

Last Updated: 2022-10-13

Revision: 2.0

Summary

A vulnerability has been identified in the Mitel Edge Gateway component of MiVoice Connect versions 19.3 (22.22.6100.0) and earlier which could allow an authenticated attacker, with internal network access, to execute arbitrary commands within the context of the system.

This vulnerability was privately reported to Mitel.

Credit is given to Patrick Bennett and Brian Pitchford of CrowdStrike for highlighting the issue and bringing to our attention.

Mitel is recommending customers with affected product versions apply the available remediation.

Affected Products

Product NameProduct VersionSecurity BulletinLast Updated
MiVoice Connect19.3 and earlier
 
22-0007-0012022-10-13

Risk Assessment

The risk for this vulnerability is rated as High. 
Refer to the product Security Bulletin for additional statements regarding risk.

Mitigation / Recommended Action

Customers are advised to review the product Security Bulletin and are advised to update their software to the latest version.

For additional information, contact Mitel Product Support.

Related CVEs / CWEs / Advisories

CVE-2022-40765

Revision History

VersionDateDescription
1.02022-10-12Initial Version
2.02022-10-13Updated bulletin with revised Knowledge Base links

Stay One Step Ahead Get notifications of the latest security advisories sent right to your inbox every week!