CVE-2023-39293: Command Injection
Published Aug 14, 2023
·Updated
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
Affected Software
6 affected components
All of the following
Any of the following
Mitel MiVoice Office 400<=7.0.9281
Mitel Mivoice Office 400 Smb Controller Firmware<=1.2.5.23
Mitel Mivoice Office 400 Smb Controller
Mitel MiVoice Office 400<=7.0.9281
Mitel Mivoice Office 400 Smb Controller Firmware<=1.2.5.23
Mitel Mivoice Office 400 Smb Controller
Event History
Aug 14, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39293?
CVE-2023-39293 is a Command Injection vulnerability found in the MiVoice Office 400 SMB Controller firmware.
2
What is the severity of CVE-2023-39293?
CVE-2023-39293 has a severity score of 9.8 (critical).
3
How does CVE-2023-39293 affect Mitel MiVoice Office 400?
CVE-2023-39293 affects Mitel MiVoice Office 400 versions up to 7.0.9281.
4
How does CVE-2023-39293 affect Mitel MiVoice Office 400 SMB Controller firmware?
CVE-2023-39293 affects Mitel MiVoice Office 400 SMB Controller firmware up to 1.2.5.23.
5
Is Mitel MiVoice Office 400 SMB Controller vulnerable to CVE-2023-39293?
Mitel MiVoice Office 400 SMB Controller is not vulnerable to CVE-2023-39293.