CVE-2022-31784

CRITICAL

Mitel Mivoice Business < 9.3.0.27 - Buffer Overflow

Title source: rule
STIX 2.1

Description

A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A successful exploit could allow arbitrary code execution.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0167
EPSS Percentile 82.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (2)
mitel/mivoice_business < 9.3.0.27
mitel/mivoice_business_express < 8.1.2.801
Published Jun 17, 2022
Tracked Since Feb 18, 2026