← לוח פגיעויות

CVE-2022-41223

בינונית 6.8 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Mitel MiVoice Connect Code Injection Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

מדדים

CVSS 3.1
6.8 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
11% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-94

מוצרים מושפעים

mitel: mivoice connect

קישורים