CVE-2023-31458: Critical severity mitel connect vulnerability
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31458?
CVE-2023-31458 is a vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier that could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges.
How severe is CVE-2023-31458?
CVE-2023-31458 has a severity level of 9 (critical).
How can an attacker exploit CVE-2023-31458?
An attacker can exploit CVE-2023-31458 by leveraging internal network access to authenticate with administrative privileges without requiring a password change during initial installation.
Which versions of Mitel MiVoice Connect are affected by CVE-2023-31458?
CVE-2023-31458 affects Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier.
Are there any mitigation steps available for CVE-2023-31458?
To mitigate CVE-2023-31458, users should ensure that a password change is enforced during initial installation of Mitel MiVoice Connect and limit internal network access to prevent unauthenticated attackers from exploiting the vulnerability.