LOGIN PORTAL
Americas
Oceania
Solutions
Business Size
Industries
Partners
App & Developers
Services
Training
Mitel User Group
Support
Partners
Unified Communications Collaboration
Contact Center
Devices
Newsroom
Customer Success
Blog
Resource Center
Careers
Location: United States
Advisory ID: 22-0008
Publish Date: 2022-10-12
Last Updated: 2022-10-13
Revision: 2.0
A vulnerability has been identified in the Director component of Mitel MiVoice Connect versions 19.3 (22.22.6100.0) and earlier which could allow an authenticated attacker, with internal network access, to execute arbitrary code within the context of the application.
This vulnerability was privately reported to Mitel.
Credit is given to Patrick Bennett of CrowdStrike for highlighting the issue and bringing to our attention.
Mitel is recommending customers with affected product versions apply the available remediation.
Product Name | Product Version | Security Bulletin | Last Updated |
---|---|---|---|
MiVoice Connect (Including earlier versions 14.2) |
19.3 and earlier |
22-0008-001 | 2022-10-13 |
The risk for this vulnerability is rated as High.
Refer to the product Security Bulletin for additional statements regarding risk.
Customers are advised to review the product Security Bulletin and are advised to implement the available remediation steps provided.
For additional information, contact Mitel Product Support.
Version | Date | Description |
---|---|---|
1.0 | 2022-10-12 | Initial Version |
2.0 |
2022-10-13 |
Updated bulletin with revised Knowledge Base links |