First published: Tue Nov 22 2022(Updated: )
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice Connect | <19.3 | |
Mitel MiVoice Connect | =19.3 | |
Mitel MiVoice Connect | ||
<19.3 | ||
=19.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40765 is a vulnerability in Mitel MiVoice Connect that allows an authenticated attacker with internal network access to execute commands within the system.
CVE-2022-40765 allows an authenticated attacker with internal network access to execute commands within the context of the system in Mitel MiVoice Connect.
The severity of CVE-2022-40765 is not mentioned in the provided information.
To fix CVE-2022-40765 in Mitel MiVoice Connect, refer to the provided security advisory from Mitel for necessary patches or updates.
You can find more information about CVE-2022-40765 in the provided security advisory from Mitel.