← Back to browse · API

CVE-2022-29499

Severity
CRITICAL
CVSS
9.8
EPSS
0.55404
Risk score
83.59
CISA KEV
Yes
PoC
No
Published
2022-04-26
Modified
2026-08-06
First seen
2026-08-07
Aliases
EUVD-2022-33836, GHSA-F4RG-W9QM-5F42
Products
Mitel:MiVoice Connect, n/a:n/a n/a
Sources
cisa.gov CVE-2022-29499
euvd EUVD-2022-33836

Description

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

References