NA

CVE-2023-39285

Published: 14/09/2023 Updated: 19/09/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect up to and including 19.3 SP3 (22.24.5800.0) could allow an unauthenticated malicious user to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an malicious user to provide a modified URL, potentially enabling them to modify system configuration settings.

Vulnerable Product Search on Vulmon Subscribe to Product

mitel mivoice connect