First published: Thu Sep 14 2023(Updated: )
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel Connect Mobility Router | <9.6.2307.111 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39286 is a vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect.
CVE-2023-39286 has a severity rating of medium (4.3).
CVE-2023-39286 allows an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack on Mitel MiVoice Connect.
An attacker can exploit CVE-2023-39286 by providing a modified request, which may lead to unauthorized actions on the affected system.
Mitel has released a security advisory (23-0015) with mitigation steps to address the vulnerability. Please refer to the provided reference for more information.