First published: Fri Aug 25 2023(Updated: )
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice Connect | <=22.24.5800.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Mitel MiVoice Connect vulnerability is CVE-2023-39287.
CVE-2023-39287 has a severity of medium (5.5).
CVE-2023-39287 affects Mitel MiVoice Connect versions up to and including 19.3 SP3 (22.24.5800.0).
The CWE ID for CVE-2023-39287 is CWE-88.
An authenticated attacker with elevated privileges and internal network access can exploit CVE-2023-39287 to conduct a command argument injection due to insufficient parameter sanitization.