First published: Fri Aug 25 2023(Updated: )
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice Connect | <=9.6.2304.102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-39288.
The Connect Mobility Router component of Mitel MiVoice Connect is affected by this vulnerability.
The severity of CVE-2023-39288 is medium with a severity score of 5.5.
This vulnerability allows an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization.
To fix CVE-2023-39288, it is recommended to apply the latest security patches or updates provided by Mitel MiVoice Connect.