Описание
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
Уязвимые конфигурации
Конфигурация 1Версия до 7.0.9281 (включая)Версия до 1.2.5.23 (включая)
Одновременно
Одно из
cpe:2.3:a:mitel:mivoice_office_400:*:*:*:*:*:*:*:*
cpe:2.3:o:mitel:mivoice_office_400_smb_controller_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitel:mivoice_office_400_smb_controller:-:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00272
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89
Связанные уязвимости
CVSS3: 9.8
github
больше 2 лет назад
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
EPSS
Процентиль: 50%
0.00272
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
CWE-89