First published: Mon Aug 14 2023(Updated: )
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel MiVoice Office 400 | <=7.0.9281 | |
Mitel Mivoice Office 400 Smb Controller Firmware | <=1.2.5.23 | |
Mitel Mivoice Office 400 Smb Controller | ||
All of | ||
Mitel Mivoice Office 400 Smb Controller | ||
Any of | ||
Mitel MiVoice Office 400 | <=7.0.9281 | |
Mitel Mivoice Office 400 Smb Controller Firmware | <=1.2.5.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39292 is a SQL Injection vulnerability identified in the MiVoice Office 400 SMB Controller through 1.2.5.23.
CVE-2023-39292 allows a malicious actor to access sensitive information and execute arbitrary database and management operations.
CVE-2023-39292 has a severity rating of 9.8 (Critical).
To fix CVE-2023-39292, it is recommended to update the MiVoice Office 400 SMB Controller to version 1.2.5.24 or later.
More information about CVE-2023-39292 can be found on the Mitel Product Security Advisory page: [link](https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008)