Vulnerability record · CVE-2022-29499 · published 26 April 2022
CVE-2022-29499: Mitel MiVoice Connect Service Appliance input validation RCE
Mitel · Mivoice Connect
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 fails to properly validate input, allowing remote code execution. The appliances involved are SA 100, SA 400, and Virtual SA. Because the flaw is remotely reachable without credentials, it is a serious risk to any internet-exposed or reachable deployment.
Description
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network reachability, CISA KEV listing with known ransomware use, and very high EPSS probability make this an urgent patching priority.
What it is
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 fails to properly validate input, allowing remote code execution. The appliances involved are SA 100, SA 400, and Virtual SA. Because the flaw is remotely reachable without credentials, it is a serious risk to any internet-exposed or reachable deployment.
Impact
An unauthenticated remote attacker can execute arbitrary code on the Service Appliance, gaining full control of the device. That can lead to data theft, service disruption, and use of the appliance as a foothold into the voice network.
Attack surface
The CVSS vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not specify the exact interface or port, so defenders should treat any reachable Service Appliance service as potentially exposed.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-06-27 with a required action date of 2022-07-18, and the KEV entry notes known ransomware campaign use. EPSS gives a 30-day exploitation probability of about 0.556 (98.9th percentile), indicating high likelihood of active exploitation.
What to do
- Apply the vendor update per Mitel Product Security Advisory 22-0002 as the first action.
- If patching cannot be done immediately, remove Service Appliances from direct internet exposure and restrict management access to trusted networks.
- Segment voice and appliance networks from general corporate and user networks to limit lateral movement.
- Monitor Mitel advisories and CISA KEV for updated guidance and confirm the fixed version before closing the finding.
- Rotate credentials and review appliance configuration for signs of tampering after any suspected exposure.
Detection
- Review Service Appliance logs for unexpected process execution, new files, or configuration changes.
- Alert on anomalous outbound connections from SA 100, SA 400, or Virtual SA hosts.
- Hunt for known exploitation indicators against the Service Appliance component using available threat intelligence.
- Audit network exposure of Service Appliances and flag any that are reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-29499 to the Known Exploited Vulnerabilities catalog on 27 June 2022 as "Mitel MiVoice Connect Data Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 | Vendor Advisory |
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499 | US Government Resource |
Track CVE-2022-29499 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29499), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.