VYPR
Unrated severityNVD Advisory· Published Aug 25, 2023· Updated Oct 2, 2024

CVE-2023-39287

CVE-2023-39287

Description

A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated attackers with elevated privileges can inject commands into Mitel MiVoice Connect Edge Gateway (≤19.3 SP3), enabling network info disclosure and traffic flooding.

Vulnerability

A command argument injection vulnerability exists in the Edge Gateway component of Mitel MiVoice Connect through version 19.3 SP3 (22.24.5800.0). The flaw arises from insufficient sanitization of parameters passed to gateway commands, allowing an authenticated attacker with elevated privileges and internal network access to inject arbitrary arguments. Affected versions include all releases prior to the patched update [1].

Exploitation

An attacker must be authenticated to the system and possess elevated privileges (e.g., administrative access) along with internal network connectivity to the Edge Gateway. No user interaction or race condition is required. The attacker crafts malicious input to a vulnerable command parameter, which the gateway executes without proper validation, leading to unintended command execution [1].

Impact

Successful exploitation enables the attacker to access sensitive network information (e.g., configuration data, traffic logs) and to generate excessive network traffic, potentially causing denial-of-service conditions or resource exhaustion. The compromise occurs at the gateway level, affecting connected network operations [1].

Mitigation

Mitel has released updated software versions to address this vulnerability. Customers are advised to upgrade to the latest release (beyond 19.3 SP3). No workarounds are documented; contacting Mitel Product Support is recommended for assistance [1]. If no fix is available for legacy deployments, consider network segmentation and access controls to limit exposure.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.