CVE-2022-29499
KEV
🔴 Łataj teraz
Błędna walidacja danych w Mitel MiVoice Connect umożliwia zdalne wykonanie kodu.
CVSS
9.8
EPSS
55.4%
Exploit
weaponized
Vendor
mitel
Opis źródłowy (NVD)
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 55.4% |
| Opublikowano (NVD) | 2022-04-26 02:15:37 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-06 05:16:37 UTC |
Referencje
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 (cve@mitre.org) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]