Skip to content
COOEY

FAIL › dossier

MiVoice Connect

PRODUCT

· dossier confidence 50%

MiVoice Connect, a Mitel product, has experienced multiple critical security failures, including RCE vulnerabilities linked to ransomware.

PROFILE
CategoryCommunicationWhat they doMiVoice Connect is a unified communications solution by Mitel that integrates voice, video, data, and mobility services.
SECURITY POSTURE

The company has faced multiple critical remote code execution (RCE) vulnerabilities, indicating a potential lack of robust security measures.

Notable failures
  • CVE-2022-41223: Authenticated internal attacker could execute code leading to ransomware.
  • CVE-2022-29499: Critical RCE flaw actively exploited in the wild linked to ransomware.
  • CVE-2022-40765: Command injection flaw allowing arbitrary commands execution with internal network access.
Patterns: Repeated unpatched RCE vulnerabilities.; Linked to ransomware exploitation.
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2023-02-21 CVE-2022-41223 critical An authenticated internal attacker could execute code in Mitel MiVoice Connect via CVE-2022-41223, a vulnerability actively exploited in the wild and linked to ransomware.
2022-06-27 CVE-2022-29499 critical Mitel MiVoice Connect suffered a critical remote code execution flaw due to incorrect data validation that was actively exploited in the wild and linked to ransomware.
2023-02-21 CVE-2022-40765 critical An authenticated attacker with internal network access can execute arbitrary commands on Mitel MiVoice Connect via a command injection flaw in the Edge Gateway component.
2022-04-26 CVE-2022-29499 critical CVE-2022-29499: The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows
Open questions: How has Mitel addressed these vulnerabilities? · What is the current state of security in MiVoice Connect? · Are there any ongoing security initiatives by Mitel?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:44:00.216894+00:00