EXPOSURES › CVE-2022-29499
CVE-2022-29499
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMitel MiVoice Connect suffered a critical remote code execution flaw due to incorrect data validation that was actively exploited in the wild and linked to ransomware.
The Service Appliance component in Mitel MiVoice Connect allowed remote code execution via incorrect data validation, a vulnerability that was actively exploited in the wild and linked to ransomware attacks. DIB organizations must ensure their telephony and collaboration systems are patched and monitored, as such flaws can lead to complete system compromise and data exfiltration. This failure highlights the risk of relying on unpatched or poorly secured third-party hardware and software in critical communications infrastructure.
Shame score — A critical RCE flaw in a widely deployed business communications system was actively exploited in the wild and linked to ransomware, indicating severe negligence and a failure to protect critical infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.