All CVEs View on NVD
CVE-2022-29499
CRITICAL9.8
CISA KEV
Published 2022-04-26 · Updated 2026-08-06 · Source cve@mitre.org
Description
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-20CWE-20
CISA Known-Exploited Vulnerability
Product: Mitel — MiVoice Connect
Name: Mitel MiVoice Connect Data Validation Vulnerability
Date added: 2022-06-27 · Due: 2022-07-18
USED IN RANSOMWARE
Required action: Apply updates per vendor instructions.

