TROYANOSYVIRUS
Back to CVEs

CVE-2022-41223

MEDIUMCISA KEV
6.8

Description

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

CVE Details

CVSS v3.1 Score6.8
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorADJACENT_NETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published11/22/2022
Last Modified11/3/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorMitel
ProductMiVoice Connect
Vulnerability NameMitel MiVoice Connect Code Injection Vulnerability
KEV Date Added2023-02-21
Remediation Due Date2023-03-14
Ransomware UseKnown

Affected Products

mitel:mivoice_connect

Weaknesses (CWE)

CWE-94CWE-94

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.