CVE-2022-41223
KEV ransomwarelargeAuthenticated Code Injection in Mitel MiVoice Connect Director (through 19.3)
CISA: Mitel MiVoice Connect Code Injection Vulnerability
CVE-2022-41223 is a code-injection flaw (CWE-94) in the Director database component of Mitel MiVoice Connect through version 19.3 (22.22.6100.0), caused by insufficient restrictions on database data types. An attacker who is already authenticated with high-privilege access to the affected component can submit specially crafted data that is injected and executed. Successful exploitation yields high-impact results — confidentiality, integrity, and availability of the system can all be compromised — and CISA notes it has seen known ransomware use. All organizations running Mitel MiVoice Connect with Director at or below the affected build are potentially exposed, with the practical attack surface limited to those who can reach the Director interface (the CVSS vector is adjacent-network with high privileges required). The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-02-21 with ransomware use confirmed, but no public proof-of-concept is known, so defenders should assume active exploitation.
What to do: Apply the vendor-supplied update for MiVoice Connect per Mitel's instructions, ensuring Director is running a build later than 19.3 (22.22.6100.0). Until patched, restrict access to the Director web component to trusted admin networks, review and harden high-privilege account credentials, and monitor for signs of exploitation given confirmed ransomware use. Check with your Mitel reseller or the vendor advisory for the exact fixed version applicable to your deployment.
| Mitel MiVoice Connect (Director database component) | through 19.3 (22.22.6100.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
- Affected
- Mitel MiVoice Connect
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- mitel
- Products
- mivoice connect
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H