CVE-2022-41223CISA KEVEPSS p95.2%

CVE-2022-41223CVE-2022-41223

mitel / mivoice_connect

Description

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

Scoring

CVSS 6.8 ()
VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS10.57% probability of exploitation · percentile 95.2% · 2026-06-18T12:00:27Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2023-02-21

(incoming)1

TypeTargetConfidenceTier
KEVEntryMitel MiVoice Connect Code Injection Vulnerabilitykev-cve-2022-412230%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2022-40765
CVE
Mitel MiVoice Connect Data Validation Vulnerability
CVE
MiCollab, MiVoice Business Express Access Control Vulnerability
CVE
Mitel MiCollab Path Traversal Vulnerability
CVE
CVE-2025-21302
CVE
CVE-2025-21339
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.