9.8
CVSSv3

CVE-2023-39292

Published: 14/08/2023 Updated: 21/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller up to and including 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitel mivoice_office_400

mitel mivoice_office_400_smb_controller_firmware