EXPOSURES › CVE-2022-40765
CVE-2022-40765
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn authenticated attacker with internal network access can execute arbitrary commands on Mitel MiVoice Connect via a command injection flaw in the Edge Gateway component.
This command injection vulnerability allows an attacker with internal network access to execute arbitrary system commands on the Mitel Edge Gateway component of MiVoice Connect. For DIB organizations, this means compromised internal networks can pivot to execute malicious code on critical telephony infrastructure, leading to potential data exfiltration, ransomware deployment, or complete system takeover. Organizations must verify their Mitel deployments are patched to versions that mitigate CVE-2022-40765 and restrict internal network access to telephony systems.
Shame score — A critical command injection flaw in a widely deployed enterprise telephony system that was actively exploited in the wild and linked to ransomware campaigns, indicating severe negligence in patching and threat monitoring.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.