Skip to main content

Mitel Releases Security Updates for Mitel MiVoice Connect and Mitel MiCollab

Mitel has released three security updates addressing vulnerabilities in Mitel MiVoice Connect and Mitel MiCollab

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Mitel has released three security updates addressing vulnerabilities in Mitel MiVoice Connect and Mitel MiCollab


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Mitel has released three security advisories to address two vulnerabilities rated as High in MiVoice Connect and one vulnerability rated as Critical in Mitel MiCollab. The MiVoice Connect vulnerabilities relate to code injection and command injection. The MiCollab vulnerability is related to authorisation control which could allow an unauthenticated attacker to upload arbitrary scripts. An attacker could exploit these vulnerabilities to take control of an affected system.

CISA adds CVE-2022-41223 and CVE-2022-40765 to Known Exploited Vulnerability Catalog

CISA has added CVE-2022-41223 and CVE-2022-40765 to the Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.


Threat updates

Date Update
22 Feb 2023 CISA has added CVE-2022-41223 and CVE-2022-40765 to the Known Exploited Vulnerabilities Catalog

This article has been updated to reflect the status of exploitation.


Remediation advice

Affected organisations are encouraged to review Mitel's Security Advisory 22-0007, Security Advisory 22-0008, and Security Advisory 22-0009 and apply any relevant updates.



Last edited: 22 February 2023 1:45 pm