CVE-2022-29499
KEV ransomwarelargeUnauthenticated RCE in Mitel MiVoice Connect Service Appliance
CISA: Mitel MiVoice Connect Data Validation Vulnerability
CVE-2022-29499 is an improper input-validation flaw (CWE-20) in the Service Appliance component (SA 100, SA 400, and Virtual SA) of Mitel MiVoice Connect, affecting releases through 19.2 SP3. A remote, unauthenticated attacker can trigger it by sending improperly validated data to the appliance over the network; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges, user interaction, or special conditions are required. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, giving the attacker a foothold on the appliance inside the organization's voice/UC environment. Any organization running a MiVoice Connect deployment that includes one of the Service Appliances is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-27 with known ransomware use, and press reports describe the Lorenz ransomware group and others exploiting this Mitel VoIP zero-day for initial access into business networks (EPSS: 55.6% chance of exploitation in 30 days).
What to do: Apply Mitel's update for the Service Appliance component per the vendor's instructions, since all releases up through 19.2 SP3 are affected; do not delay, as ransomware groups are actively exploiting the flaw for initial access. Identify whether your MiVoice Connect deployment includes an SA 100, SA 400, or Virtual SA, restrict the appliance's web interface from direct internet exposure until patched, and after updating check the appliance for signs of compromise or follow-on ransomware activity.
| Mitel MiVoice Connect | through 19.2 SP3 |
| Mitel MiVoice Connect Service Appliance (SA 100, SA 400, Virtual SA) | Service Appliance component in MiVoice Connect through 19.2 SP3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
- Affected
- Mitel MiVoice Connect
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- mitel
- Products
- mivoice connect
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H