VYPR
Unrated severityNVD Advisory· Published Sep 14, 2023· Updated Sep 25, 2024

CVE-2023-39285

CVE-2023-39285

Description

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A CSRF vulnerability in Mitel MiVoice Connect Edge Gateway allows unauthenticated attackers to modify system configuration via a crafted URL.

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Edge Gateway component of Mitel MiVoice Connect. The issue stems from insufficient request validation, allowing an attacker to craft a malicious URL that, when visited by an authenticated user, can perform unauthorized actions. Affected versions include MiVoice Connect 19.3 SP3 HF1 (22.24.6900.0) and earlier [1].

Exploitation

An unauthenticated attacker with network access can exploit this vulnerability by tricking an authenticated user into clicking a specially crafted link. The attacker does not need any prior authentication or privileges. The crafted URL, when processed by the victim's browser, sends a request to the Edge Gateway that appears legitimate, thereby executing actions with the victim's session credentials [1].

Impact

Successful exploitation allows the attacker to modify system configuration settings within the MiVoice Connect environment. This could lead to unauthorized changes in network settings, user permissions, or other critical parameters, potentially compromising the integrity and availability of the communication system [1].

Mitigation

Mitel has released software updates to address this vulnerability. Customers are advised to upgrade to the latest version of MiVoice Connect. No workaround is currently available. For specific version information, contact Mitel Product Support [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.