CVE-2022-40765: Mitel MiVoice Connect Command Injection Vulnerability
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
Other sources
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mitel MiVoice Connect (Edge Gateway)to a version that resolves this vulnerability.Fixed in 19.3 (22.22.6100.0)Patch Mitel MiVoice Connect Command Injection Vulnerability
Event History
Frequently Asked Questions
What is CVE-2022-40765?
CVE-2022-40765 is a vulnerability in Mitel MiVoice Connect that allows an authenticated attacker with internal network access to execute commands within the system.
How does CVE-2022-40765 affect Mitel MiVoice Connect?
CVE-2022-40765 allows an authenticated attacker with internal network access to execute commands within the context of the system in Mitel MiVoice Connect.
What is the severity of CVE-2022-40765?
The severity of CVE-2022-40765 is not mentioned in the provided information.
How can I fix CVE-2022-40765 in Mitel MiVoice Connect?
To fix CVE-2022-40765 in Mitel MiVoice Connect, refer to the provided security advisory from Mitel for necessary patches or updates.
Where can I find more information about CVE-2022-40765?
You can find more information about CVE-2022-40765 in the provided security advisory from Mitel.