Arbitrary Script Execution Vulnerability in Mitel MiVoice Connect Headquarters Server

Arbitrary Script Execution Vulnerability in Mitel MiVoice Connect Headquarters Server

CVE-2023-31457 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

Learn more about our Cis Benchmark Audit For Server Software.