Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31784

Опубликовано: 17 июн. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 6.8
EPSS Низкий

Описание

A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A successful exploit could allow arbitrary code execution.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mitel:mivoice_business:*:*:*:*:*:*:*:*
Версия до 9.3.0.27 (включая)
cpe:2.3:a:mitel:mivoice_business_express:*:*:*:*:*:*:*:*
Версия до 8.1.2.801 (включая)

EPSS

Процентиль: 82%
0.01666
Низкий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient validation of URL parameters. A successful exploit could allow arbitrary code execution.

EPSS

Процентиль: 82%
0.01666
Низкий

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-120