First published: Tue Apr 26 2022(Updated: )
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice Connect | <=22.20.2300.0 | |
Mitel MiVoice Connect | ||
<=22.20.2300.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-29499.
The severity of CVE-2022-29499 is critical with a score of 9.8.
CVE-2022-29499 affects Mitel MiVoice Connect through version 19.2 SP3.
The vulnerability in Mitel MiVoice Connect occurs due to incorrect data validation in the Service Appliance component.
To fix the vulnerability in Mitel MiVoice Connect, it is recommended to apply the necessary patches provided by Mitel.