Privilege Escalation Vulnerability in Mitel MiVoice Connect Edge Gateway
CVE-2023-31458
9.8CRITICAL
What is CVE-2023-31458?
The vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier allows an attacker with internal network access to exploit the system due to the initial installation process not enforcing a mandatory password change. This oversight could lead to unauthorized administrative access, enabling the attacker to perform arbitrary configuration changes and execute commands at will, potentially compromising the integrity and security of the entire system.