VulnerabilityAnalyzed
CVE-2022-29499
Mitel MiVoice Connect Data Validation Vulnerability
KEVCRITICAL 9.8EPSS 55.6%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 18 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 55.60% probability · 99th percentile
- CISA KEV
- Listed 27 June 2022 · due 18 July 2022 · used in ransomware campaigns
- Weakness
- CWE-20
- Affected
- mitel/mivoice connect
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-29499
References
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002Vendor Advisory
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.