← Vulnerability feed

Vulnerability record · CVE-2022-29499 · published 26 April 2022

CVE-2022-29499: Mitel MiVoice Connect Service Appliance input validation RCE

Mitel · Mivoice Connect

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 fails to properly validate input, allowing remote code execution. The appliances involved are SA 100, SA 400, and Virtual SA. Because the flaw is remotely reachable without credentials, it is a serious risk to any internet-exposed or reachable deployment.

9.8 CVSS 3.1 Critical CISA KEV since 27 Jun 2022 Known ransomware use EPSS 55% · top 1.0% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
55%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
6 Aug 2026Last modified by NVD

Description

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network reachability, CISA KEV listing with known ransomware use, and very high EPSS probability make this an urgent patching priority.

What it is

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 fails to properly validate input, allowing remote code execution. The appliances involved are SA 100, SA 400, and Virtual SA. Because the flaw is remotely reachable without credentials, it is a serious risk to any internet-exposed or reachable deployment.

Impact

An unauthenticated remote attacker can execute arbitrary code on the Service Appliance, gaining full control of the device. That can lead to data theft, service disruption, and use of the appliance as a foothold into the voice network.

Attack surface

The CVSS vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not specify the exact interface or port, so defenders should treat any reachable Service Appliance service as potentially exposed.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2022-06-27 with a required action date of 2022-07-18, and the KEV entry notes known ransomware campaign use. EPSS gives a 30-day exploitation probability of about 0.556 (98.9th percentile), indicating high likelihood of active exploitation.

What to do

  • Apply the vendor update per Mitel Product Security Advisory 22-0002 as the first action.
  • If patching cannot be done immediately, remove Service Appliances from direct internet exposure and restrict management access to trusted networks.
  • Segment voice and appliance networks from general corporate and user networks to limit lateral movement.
  • Monitor Mitel advisories and CISA KEV for updated guidance and confirm the fixed version before closing the finding.
  • Rotate credentials and review appliance configuration for signs of tampering after any suspected exposure.

Detection

  • Review Service Appliance logs for unexpected process execution, new files, or configuration changes.
  • Alert on anomalous outbound connections from SA 100, SA 400, or Virtual SA hosts.
  • Hunt for known exploitation indicators against the Service Appliance component using available threat intelligence.
  • Audit network exposure of Service Appliances and flag any that are reachable from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-29499 to the Known Exploited Vulnerabilities catalog on 27 June 2022 as "Mitel MiVoice Connect Data Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29499 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2022-41223Mitel MiVoice Connect Director database code injectionThe Director database component of MiVoice Connect through 19.3 (22.22.6100.0) fails to sufficiently restrict database data types, allowing crafted d…KEVEPSS 11%analysed6.8CVE-2022-40765Mitel MiVoice Connect Edge Gateway command injectionMitel MiVoice Connect through 19.3 (22.22.6100.0) contains a command-injection flaw in the Edge Gateway component caused by insufficient restriction …KEVEPSS 11%analysed9.8CVE-2023-32748Mitel mivoice connect incorrect authorization vulnerabilityThe Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network…EPSS 0.90%9.8CVE-2023-31458Mitel mivoice connect vulnerabilityA vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated at…EPSS 0.92%9.8CVE-2023-31457Mitel mivoice connect vulnerabilityA vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthentic…EPSS 0.99%9.8CVE-2020-10211Mitel mivoice connect improper input validation vulnerabilityA remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1 could allow an unauthenticated remote attacker to exe…EPSS 3.0%8.8CVE-2023-31459Mitel mivoice connect weak password recovery vulnerabilityA vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated at…EPSS 0.39%7.5CVE-2023-39289Mitel mivoice connect information exposure vulnerabilityA vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to con…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2022-29499), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.