CVE-2023-39287: Medium severity mitel connect vulnerability
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mitel MiVoice Connect vulnerability?
The vulnerability ID for this Mitel MiVoice Connect vulnerability is CVE-2023-39287.
What is the severity of CVE-2023-39287?
CVE-2023-39287 has a severity of medium (5.5).
How does CVE-2023-39287 affect Mitel MiVoice Connect?
CVE-2023-39287 affects Mitel MiVoice Connect versions up to and including 19.3 SP3 (22.24.5800.0).
What is the CWE ID for CVE-2023-39287?
The CWE ID for CVE-2023-39287 is CWE-88.
How can the Mitel MiVoice Connect CVE-2023-39287 vulnerability be exploited?
An authenticated attacker with elevated privileges and internal network access can exploit CVE-2023-39287 to conduct a command argument injection due to insufficient parameter sanitization.