ZeroHour

CVE-2022-29499

KEV ransomwarelarge

Unauthenticated RCE in Mitel MiVoice Connect Service Appliance

CISA: Mitel MiVoice Connect Data Validation Vulnerability

CVSS 3.1
9.8 critical
EPSS
56%p99
Published
()
KEV added
AI analysis

CVE-2022-29499 is an improper input-validation flaw (CWE-20) in the Service Appliance component (SA 100, SA 400, and Virtual SA) of Mitel MiVoice Connect, affecting releases through 19.2 SP3. A remote, unauthenticated attacker can trigger it by sending improperly validated data to the appliance over the network; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges, user interaction, or special conditions are required. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, giving the attacker a foothold on the appliance inside the organization's voice/UC environment. Any organization running a MiVoice Connect deployment that includes one of the Service Appliances is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-27 with known ransomware use, and press reports describe the Lorenz ransomware group and others exploiting this Mitel VoIP zero-day for initial access into business networks (EPSS: 55.6% chance of exploitation in 30 days).

What to do: Apply Mitel's update for the Service Appliance component per the vendor's instructions, since all releases up through 19.2 SP3 are affected; do not delay, as ransomware groups are actively exploiting the flaw for initial access. Identify whether your MiVoice Connect deployment includes an SA 100, SA 400, or Virtual SA, restrict the appliance's web interface from direct internet exposure until patched, and after updating check the appliance for signs of compromise or follow-on ransomware activity.

Affected
Mitel MiVoice Connectthrough 19.2 SP3
Mitel MiVoice Connect Service Appliance (SA 100, SA 400, Virtual SA)Service Appliance component in MiVoice Connect through 19.2 SP3
Estimated exposure
largeestimated tens of thousands of business deployments with thousands of internet-exposed Service Appliances (clearly an estimate) — Mitel is a major on-premises unified-communications vendor with a large MiVoice Connect installed base, and public internet scans have identified thousands of exposed Mitel Service Appliances; only deployments using the SA 100/SA…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

CISA Known Exploited Vulnerability
Affected
Mitel MiVoice Connect
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
mitel
Products
mivoice connect
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news