← Zuruck zu CVEs
CVE-2022-31784
CRITICAL9.8
Beschreibung
A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A successful exploit could allow arbitrary code execution.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht6/17/2022
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
mitel:mivoice_businessmitel:mivoice_business_express
Schwachen (CWE)
CWE-120
Referenzen
https://www.mitel.com/support/security-advisories(cve@mitre.org)
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0005(cve@mitre.org)
https://www.mitel.com/support/security-advisories(af854a3a-2127-422b-91ae-364da2661108)
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0005(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.