Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 14, 2023

CVE-2022-40765

High
EPSS 2.5%CISA KEVRansomware
Mitel/MiVoice Connect

Description

The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

EPSS — Exploit Probability

2.5%

Higher than 85.2% of all CVEs

Required Action

https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0007; https://nvd.nist.gov/vuln/detail/CVE-2022-40765

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
2.5%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Feb 21, 2023

Added to KEV

Feb 21, 2023

Remediation Due

Mar 14, 2023

Affected Product

Mitel

MiVoice Connect

View all Mitel CVEs