Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown
CVE-2022-40765
Disclosure Date: November 22, 2022 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.
1
Attacker Value
Unknown
CVE-2022-41223
Disclosure Date: November 22, 2022 (last updated October 08, 2023)
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
1
Attacker Value
Unknown
CVE-2023-39285
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.
0
Attacker Value
Unknown
CVE-2023-39291
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.
0
Attacker Value
Unknown
CVE-2023-39290
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.
0
Attacker Value
Unknown
CVE-2023-39289
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information.
0
Attacker Value
Unknown
CVE-2023-39288
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
0
Attacker Value
Unknown
CVE-2023-39287
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
0
Attacker Value
Unknown
CVE-2023-32748
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
0
Attacker Value
Unknown
CVE-2023-31458
Disclosure Date: May 24, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.
0