A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
2023-08-14T19:15:12.897
2024-11-21T08:15:05.180
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mitel | mivoice_office_400 | ≤ 7.0.9281 | Yes |
Operating System | mitel | mivoice_office_400_smb_controller_firmware | ≤ 1.2.5.23 | Yes |
Hardware | mitel | mivoice_office_400_smb_controller | - | No |