The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMitel Mivoice Connect
APPMitel≤ 22.24.1500.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2022-29499CRITICAL9.8⚠ KEVPL ✓same product
RCE w komponencie Service Appliance Mitel MiVoice Connect
CVE-2023-31457CRITICAL9.8PL ✓same product
Mitel MiVoice Connect — ominięcie autoryzacji w komponencie Headquarters
CVE-2023-31458CRITICAL9.8PL ✓same product
Mitel MiVoice Connect – pominięcie uwierzytelnienia w Edge Gateway
CVE-2020-10211CRITICAL9.8PL ✓same product
RCE w komponencie UCB Mitel MiVoice Connect — brak walidacji parametrów URL
CVE-2023-39289HIGH7.5same product
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could a...