VYPR

Mivoice Office 400

by Mitel

CVEs (3)

  • CVE-2023-39293CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.

  • CVE-2023-39292CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.

  • CVE-2018-16226MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful…