Vulnerability Description
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitel | Mivoice Office 400 | <= 7.0.9281 |
| Mitel | Mivoice Office 400 Smb Controller Firmware | <= 1.2.5.23 |
| Mitel | Mivoice Office 400 Smb Controller | - |
Related Weaknesses (CWE)
References
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisorVendor Advisory
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisorVendor Advisory
FAQ
What is CVE-2023-39293?
CVE-2023-39293 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of ...
How severe is CVE-2023-39293?
CVE-2023-39293 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-39293?
Check the references section above for vendor advisories and patch information. Affected products include: Mitel Mivoice Office 400, Mitel Mivoice Office 400 Smb Controller Firmware, Mitel Mivoice Office 400 Smb Controller.