Umbra Wiki cve cve/CVE-2022-41223
Back to wiki

CVE-2022-41223 — Mitel MiVoice Connect Code Injection Vulnerability

provenance: imported · CVE: CVE-2022-41223

CVE-2022-41223: Mitel MiVoice Connect Code Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Mitel
Product MiVoice Connect
Date added 2023-02-21
Due date 2023-03-14
Ransomware campaign use Known

Description

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008; https://nvd.nist.gov/vuln/detail/CVE-2022-41223

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-41223
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog