peter bassill · operator
$ cve CVE-2022-41223 JSON

CVE-2022-41223 KEV

6.8
MEDIUM · CVSS 3.1 · EPSS 10.7% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2023-03-14.

Description

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

Scoring

CVSS6.8 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS10.66% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2023-03-14
Public exploitnone known
Published2022-11-22
Last modified2026-06-17

CISA KEV

NameMitel MiVoice Connect Code Injection Vulnerability
Added2023-02-21
Due2023-03-14
Vendor / productMitel / MiVoice Connect
Ransomware useknown

Affected (1)

VendorProduct
mitelmivoice connect

References

→ the Explorer  ·  watch your stack  ·  NVD