CVE-2022-29499 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 54.3% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-07-18.
Description
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 54.32% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | yes — remediate by 2022-07-18 |
| Public exploit | none known |
| Published | 2022-04-26 |
| Last modified | 2026-08-06 |
CISA KEV
| Name | Mitel MiVoice Connect Data Validation Vulnerability |
|---|---|
| Added | 2022-06-27 |
| Due | 2022-07-18 |
| Vendor / product | Mitel / MiVoice Connect |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| mitel | mivoice connect |
References
→ the Explorer · watch your stack · NVD