CVE-2022-41223
CVE-2022-41223 is a medium-severity vulnerability in Mitel Mivoice Connect with a CVSS 3.x base score of 6.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2023-02-21). The underlying weakness is classified as CWE-94.
Key facts
- Severity: Medium (CVSS 3.x base score 6.8)
- EPSS exploit prediction: 11% (96th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2023-02-21)
- EU (EUVD) id: EUVD-2022-44464
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2023-02-21)
- Weakness: CWE-94
- Affected product: Mitel Mivoice Connect
- Published:
- Last modified:
Description
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
Frequently asked questions
- What is CVE-2022-41223?
- The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
- How severe is CVE-2022-41223?
- CVE-2022-41223 has a CVSS 3.x base score of 6.8, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2022-41223 being actively exploited?
- Yes. CVE-2022-41223 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2023-02-21, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2022-41223?
- CVE-2022-41223 affects Mitel Mivoice Connect. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2022-41223?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2022-41223 have an EU (EUVD) identifier?
- Yes. CVE-2022-41223 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2022-44464. It is also flagged as exploited in the EUVD (since 2023-02-21).
- When was CVE-2022-41223 published?
- CVE-2022-41223 was published on 2022-11-22 and last updated on 2026-06-17.
References
- https://www.mitel.com/support/security-advisories
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41223
Affected products (1)
- cpe:2.3:a:mitel:mivoice_connect:*:*:*:*:*:*:*:*
More vulnerabilities in Mitel Mivoice Connect
- CVE-2023-32748 — Critical (CVSS 9.8): The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated…
- CVE-2023-31458 — Critical (CVSS 9.8): A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier…
- CVE-2023-31457 — Critical (CVSS 9.8): A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and…
- CVE-2022-29499 — Critical (CVSS 9.8): The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of…
- CVE-2020-10211 — Critical (CVSS 9.8): A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an…
- CVE-2023-31459 — High (CVSS 8.8): A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier…
All CVEs affecting Mitel Mivoice Connect →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-93603 — Critical (CVSS 10.0): vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its…
- CVE-2026-92937 — Critical (CVSS 10.0): vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for…
- CVE-2026-62104 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
- CVE-2026-73456 — Critical (CVSS 10.0): Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface…
- CVE-2026-73453 — Critical (CVSS 10.0): An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary…
- CVE-2026-53710 — Critical (CVSS 10.0): MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the…