CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-32748

CVSS 9.8v3.1pub. 2023-08-14upd. 2024-11-21

The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Mitel Mivoice Connect

    APP
    Mitel
    ≤ 22.24.1500.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-29499CRITICAL9.8⚠ KEVPL ✓same product

RCE w komponencie Service Appliance Mitel MiVoice Connect

CVE-2023-31457CRITICAL9.8PL ✓same product

Mitel MiVoice Connect — ominięcie autoryzacji w komponencie Headquarters

CVE-2023-31458CRITICAL9.8PL ✓same product

Mitel MiVoice Connect – pominięcie uwierzytelnienia w Edge Gateway

CVE-2020-10211CRITICAL9.8PL ✓same product

RCE w komponencie UCB Mitel MiVoice Connect — brak walidacji parametrów URL

CVE-2023-39289HIGH7.5same product

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could a...