TROYANOSYVIRUS
Back to CVEs

CVE-2022-40765

MEDIUMCISA KEV
6.8

Description

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

CVE Details

CVSS v3.1 Score6.8
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published11/22/2022
Last Modified11/3/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorMitel
ProductMiVoice Connect
Vulnerability NameMitel MiVoice Connect Command Injection Vulnerability
KEV Date Added2023-02-21
Remediation Due Date2023-03-14
Ransomware UseKnown

Affected Products

mitel:mivoice_connect

Weaknesses (CWE)

CWE-77CWE-77

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.