Loading vulnerability details…
CVSS v3.1
9.8
EPSS
55.40%
Published
Apr 25, 2022
Modified
Aug 6, 2026
CISA Known Exploited Vulnerability
Added: 2022-06-27 · Due: 2022-07-18
Apply updates per vendor instructions.
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (1)
References (3)