Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 14, 2023

CVE-2022-41223

High
EPSS 2.0%CISA KEVRansomware
Mitel/MiVoice Connect

Description

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

EPSS — Exploit Probability

2.0%

Higher than 83.4% of all CVEs

Required Action

https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008; https://nvd.nist.gov/vuln/detail/CVE-2022-41223

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
2.0%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Feb 21, 2023

Added to KEV

Feb 21, 2023

Remediation Due

Mar 14, 2023

Affected Product

Mitel

MiVoice Connect

View all Mitel CVEs