ZeroHour

CVE-2022-40765

KEV ransomwarelarge

Authenticated Command Injection in Mitel MiVoice Connect Edge Gateway

CISA: Mitel MiVoice Connect Command Injection Vulnerability

CVSS 3.1
6.8 medium
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2022-40765 is a command-injection flaw (CWE-77) in the Edge Gateway component of Mitel MiVoice Connect through version 19.3 (22.22.6100.0), caused by insufficient restriction of URL parameters. An attacker who has already authenticated and holds internal network access can pass maliciously crafted URL parameters to the Edge Gateway, causing arbitrary commands to be executed on the system. Successful exploitation carries high impact to confidentiality, integrity, and availability (CVSS 3.1: 6.8, adjacent network, high privileges required), and could give a foothold that ransomware operators can leverage. Organizations running on-premises Mitel MiVoice Connect with the Edge Gateway component deployed are affected. The vulnerability is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-21 with known ransomware use, and EPSS assigns it a 10.5% probability of exploitation in the next 30 days (95th percentile).

What to do: Apply Mitel's patched MiVoice Connect release per vendor instructions (as required by CISA's KEV listing), upgrading to a version newer than 19.3 (22.22.6100.0). Until patched, restrict which internal accounts and hosts can reach the Edge Gateway, since exploitation requires high-privilege authentication and internal network access, and review Edge Gateway logs for anomalous URL parameter usage. Given known ransomware use, prioritize patching internet-reachable or edge-connected deployments and hunt for post-exploitation activity.

Affected
Mitel MiVoice Connect (Edge Gateway component)through 19.3 (22.22.6100.0)
Estimated exposure
largetens of thousands of deployments (order of magnitude 10k-100k systems, estimated) — MiVoice Connect is Mitel's widely deployed on-premises business telephony/UC platform (inherited from ShoreTel) with a footprint in the tens of thousands of business sites, though public counts of Edge Gateway-specific deployments are not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

CISA Known Exploited Vulnerability
Affected
Mitel MiVoice Connect
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
mitel
Products
mivoice connect
Weakness
CWE-77
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news