The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
References
Configurations
History
22 Oct 2025, 00:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 06:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 - Vendor Advisory |
05 May 2022, 18:25
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-20 | |
| CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
| CPE | cpe:2.3:a:mitel:mivoice_connect:*:*:*:*:*:*:*:* | |
| References | (CONFIRM) https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 - Vendor Advisory |
26 Apr 2022, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2022-04-26 02:15
Updated : 2025-10-22 00:18
NVD link : CVE-2022-29499
Mitre link : CVE-2022-29499
CVE.ORG link : CVE-2022-29499
JSON object : View
Products Affected
mitel
- mivoice_connect
CWE
CWE-20
Improper Input Validation
