Command Argument Injection Vulnerability in Mitel MiVoice Connect Edge Gateway
CVE-2023-39287
5.5MEDIUM
Summary
A vulnerability exists in the Edge Gateway of Mitel's MiVoice Connect, impacting versions through 19.3 SP3. This flaw allows authenticated users with elevated privileges and access to the internal network to execute command argument injection attacks, resulting from inadequate sanitization of input parameters. An attacker exploiting this vulnerability could potentially access sensitive network details and induce excessive network traffic, affecting overall system performance.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved