A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to execute arbitrary scripts due to insufficient validation of URL parameters. A successful exploit could allow an attacker to gain access to sensitive information.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMitel Mivoice Connect
APPMitel< 22.11.4900.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
Related vulnerabilities
CVE-2022-29499CRITICAL9.8⚠ KEVPL ✓same product
RCE w komponencie Service Appliance Mitel MiVoice Connect
CVE-2023-32748CRITICAL9.8PL ✓same product
Mitel MiVoice Connect — obejście uwierzytelniania w komponencie Linux DVS
CVE-2023-31458CRITICAL9.8PL ✓same product
Mitel MiVoice Connect – pominięcie uwierzytelnienia w Edge Gateway
CVE-2023-31457CRITICAL9.8PL ✓same product
Mitel MiVoice Connect — ominięcie autoryzacji w komponencie Headquarters
CVE-2023-39289HIGH7.5same product
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could a...