Attackers exploited a Mitel VOIP zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-29499 | Unauthenticated RCE in Mitel MiVoice Connect Service Appliance CVE-2022-29499 is an improper input-validation flaw (CWE-20) in the Service Appliance component (SA 100, SA 400, and Virtual SA) of Mitel MiVoice Connect, affecting releases through 19.2 SP3. A remote, unauthenticated attacker can trigger it by sending improperly validated data to the appliance over the network; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges, user interaction, or special conditions are required. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, giving the attacker a foothold on the appliance inside the organization's voice/UC environment. Any organization running a MiVoice Connect deployment that includes one of the Service Appliances is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-27 with known ransomware use, and press reports describe the Lorenz ransomware group and others exploiting this Mitel VoIP zero-day for initial access into business networks (EPSS: 55.6% chance of exploitation in 30 days). Do: Apply Mitel's update for the Service Appliance component per the vendor's instructions, since all releases up through 19.2 SP3 are affected; do not delay, as ransomware groups are actively exploiting the flaw for initial access. Identify whether your MiVoice Connect deployment includes an SA 100, SA 400, or Virtual SA, restrict the appliance's web interface from direct internet exposure until patched, and after updating check the appliance for signs of compromise or follow-on ransomware activity. | 9.8 | 56% | KEV ransomware |
| largeestimated tens of thousands of business deployments with thousands of internet-exposed Service Appliances (clearly an estimate) |
Full article499 words · extracted from securityaffairs.com · click to collapse

Experts warn threat actors have exploited a zero-day vulnerability in a Mitel VoIP appliance in a ransomware attack.
CrowdStrike researchers recently investigated the compromise of a Mitel VOIP appliance as an entry point in a ransomware attack against the network of an organization.
The attackers exploited a remote code execution zero-day vulnerability on the Mitel appliance to gain initial access to the target environment. The zero-day was coded as CVE-2022-29499 and received a CVSS score of 9.8.
“A vulnerability has been identified in the Mitel Service Appliance component of MiVoice Connect (Mitel Service Appliances – SA 100, SA 400, and Virtual SA) which could allow a malicious actor to perform remote code execution (CVE-2022-29499) within the context of the Service Appliance.” reads the advisory for this flaw published by the vendor.
The experts determined that the malicious activity had originated from an internal IP address associated with a Linux-based Mitel VOIP appliance sitting on the network perimeter that did not have the CrowdStrike Falcon sensor installed on it.
The forensic investigation revealed that the attackers attempted to remove the files and overwrite free space on the device.
The attack chain involved two HTTP GET requests used to retrieve a specific resource from a remote server and execute the malicious code.
“The exploit involved two GET requests. The first request targeted a get_url parameter of a php file, populating the parameter with a URL to a local file on the device. This caused the second request to originate from the device itself, which led to exploitation.” reads the analysis published by Crowdstrike experts. “This first request was necessary because the actual vulnerable URL was restricted from receiving requests from external IP addresses.”
The responses to the requests demonstrated that the threat actors used the exploit to create a reverse shell.
Once created the reverse shell, the attacker set up a web shell named pdf_import.php.
The threat actor also downloaded the Chisel tunneling/proxy tool onto the VOIP appliance, then renamed it memdump before executing it. The attackers used the tool as a reverse proxy to allow the threat actor to make lateral movements within the environment via the VOIP device.
“when threat actors exploit an undocumented vulnerability, timely patching becomes irrelevant.” concludes the report. “Critical assets should be isolated from perimeter devices to the extent possible. Ideally, if a threat actor compromises a perimeter device, it should not be possible to access critical assets via “one hop” from the compromised device. In particular, it’s critical to isolate and limit access to virtualization hosts or management servers such as ESXi and vCenter systems as much as possible. This can involve jump-boxes, network segmentation and/or multifactor authentication (MFA) requirements. “
The popular security researcher Kevin Beaumont reported there are nearly tens of thousand devices publicly accessible, most of them in the U.S., followed by the U.K., Canada, and France.
https://twitter.com/GossiTheDog/status/1540354721931841537
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Mitel VOIP)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/132588/hacking/mitel-voip-ransomware-attack.html