Umbra Wiki cve cve/CVE-2022-41223
Back to wiki

CVE-2022-41223 — Mitel MiVoice Connect Code Injection Vulnerability

provenance: imported · CVE: CVE-2022-41223 · CWE: CWE-94

CVE-2022-41223: Mitel MiVoice Connect Code Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Mitel
Product MiVoice Connect
Date added 2023-02-21
Due date 2023-03-14
Ransomware campaign use Known

Description

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008; https://nvd.nist.gov/vuln/detail/CVE-2022-41223

Weakness behind it

CISA records this vulnerability as an instance of CWE-94. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-41223
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →