PT-2023-23342 · Mitel · Mivoice Connect

Jahmil Williams

+1

·

Published

2023-05-24

·

Updated

2023-06-01

·

CVE-2023-31460

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MiVoice Connect versions 9.6.2208.101 and earlier
Description A vulnerability in the Connect Mobility Router component could allow an authenticated attacker with internal network access to conduct a command injection attack due to insufficient restriction on URL parameters.
Recommendations For versions 9.6.2208.101 and earlier, update to a version later than 9.6.2208.101 to resolve the issue.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-31460

Affected Products

Mivoice Connect