Mitel Releases Security Updates for Mitel MiVoice Connect and Mitel MiCollab
Mitel has released three security updates addressing vulnerabilities in Mitel MiVoice Connect and Mitel MiCollab
Summary
Mitel has released three security updates addressing vulnerabilities in Mitel MiVoice Connect and Mitel MiCollab
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Mitel has released three security advisories to address two vulnerabilities rated as High in MiVoice Connect and one vulnerability rated as Critical in Mitel MiCollab. The MiVoice Connect vulnerabilities relate to code injection and command injection. The MiCollab vulnerability is related to authorisation control which could allow an unauthenticated attacker to upload arbitrary scripts. An attacker could exploit these vulnerabilities to take control of an affected system.
CISA adds CVE-2022-41223 and CVE-2022-40765 to Known Exploited Vulnerability Catalog
CISA has added CVE-2022-41223 and CVE-2022-40765 to the Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
Threat updates
| Date | Update |
|---|---|
| 22 Feb 2023 |
CISA has added CVE-2022-41223 and CVE-2022-40765 to the Known Exploited Vulnerabilities Catalog
This article has been updated to reflect the status of exploitation. |
Remediation advice
Affected organisations are encouraged to review Mitel's Security Advisory 22-0007, Security Advisory 22-0008, and Security Advisory 22-0009 and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 22 February 2023 1:45 pm