CVE-2022-40765

CVE Published 2022-11-22
Related CWE(s) CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Related Vendor(s) mitel
Related Product(s) mivoice_connect
Exploitation Reported (CISA KEV) 2023-02-21
CVSS 3 Base Score 6.8 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector ADJACENT_NETWORK

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References