CVE-2023-39292: SQL Injection
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39292?
CVE-2023-39292 is a SQL Injection vulnerability identified in the MiVoice Office 400 SMB Controller through 1.2.5.23.
How does CVE-2023-39292 impact the MiVoice Office 400 SMB Controller?
CVE-2023-39292 allows a malicious actor to access sensitive information and execute arbitrary database and management operations.
What is the severity of CVE-2023-39292?
CVE-2023-39292 has a severity rating of 9.8 (Critical).
How can I fix CVE-2023-39292?
To fix CVE-2023-39292, it is recommended to update the MiVoice Office 400 SMB Controller to version 1.2.5.24 or later.
Where can I find more information about CVE-2023-39292?
More information about CVE-2023-39292 can be found on the Mitel Product Security Advisory page: [link](https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008)