CVE-2022-40765CISA KEVEPSS p95.2%

CVE-2022-40765CVE-2022-40765

mitel / mivoice_connect

Description

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.

Scoring

CVSS 6.8 ()
VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS10.48% probability of exploitation · percentile 95.2% · 2026-06-19T12:03:05Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2023-02-21

(incoming)1

TypeTargetConfidenceTier
KEVEntryMitel MiVoice Connect Command Injection Vulnerabilitykev-cve-2022-407650%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2022-41223
CVE
Mitel MiVoice Connect Data Validation Vulnerability
CVE
Mitel SIP Phones Argument Injection Vulnerability
CVE
MiCollab, MiVoice Business Express Access Control Vulnerability
CVE
Mitel MiCollab Path Traversal Vulnerability
CVE
CVE-2025-28231
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.