Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-31459

Опубликовано: 24 мая 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mitel:mivoice_connect:*:*:*:*:*:*:*:*
Версия до 9.6.2208.101 (включая)

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-640
CWE-640

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-640
CWE-640