Umbra Wiki cve cve/CVE-2022-40765
Back to wiki

CVE-2022-40765 — Mitel MiVoice Connect Command Injection Vulnerability

provenance: imported · CVE: CVE-2022-40765

CVE-2022-40765: Mitel MiVoice Connect Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Mitel
Product MiVoice Connect
Date added 2023-02-21
Due date 2023-03-14
Ransomware campaign use Known

Description

The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0007; https://nvd.nist.gov/vuln/detail/CVE-2022-40765

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-40765
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog