Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Some critical vulnerabilities in Mitel MiVoice Connect

Keira Austin by Keira Austin
May 25, 2023
in World
0
Some critical vulnerabilities in Mitel MiVoice Connect
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Mitel warns of some critical security gaps in MiVoice Connect and Connect Mobility Router. This allows attackers from the local network to execute arbitrary code. The manufacturer provides updates that are intended to close the gaps.

MiVoice Connect: Critical vulnerability

In the server components Headquarters, Windows DVS and Linux DVS there is only insufficient access control, explains Mitel in a security advisory. Unauthenticated attackers from the local network can abuse this to run arbitrary scripts (CVE-2023-31457, CVE-2023-32748; no CVSS value yet, risk “critical“). In the MiVoice Connect edge gateway, malicious actors can gain admin privileges based on default passwords (CVE-2023-31458, no CVSS, risk “hoch“).

Cross-site scripting vulnerabilities in the index.php and test_presenter.php pages of the MiVoice Connect conference component allow attackers to execute arbitrary script code (CVE-2023-25598, CVE-2023-25599; no CVSS value, risk”middle“). Are affected MiVoice-Connect-Version up to and including 19.3 SP2 (22.24.1500.0). Updated software is available that fixes the vulnerabilities. Mitel recommends that customers also ensure that complex passwords are assigned to all Edge Gateway accounts.

In the Connect Mobility Router, Mitel has also opted for standard passwords, allowing malicious actors access with administrator rights (CVE-2023-31459, no CVSS value, risk “hoch“). Authenticated attackers can use another vulnerability to inject commands that Connect Mobility Router executes in the system context. Mitel does not provide any information on what the vulnerability looks like (CVE-2023-31460, no CVSS value, risk “hoch“).

The security-critical errors can be found in the Connect Mobility Router Version 9.6.2208.101 and previous. Newer software versions iron them out. In addition, Mitel recommends that customers ensure that the accounts on the Connect Mobility Router are provided with complex passwords.

Security gaps in Mitel’s MiVoice products have often been exploited by attackers in the past. IT managers should therefore download and install the available software updates as soon as possible.

(dmk)

To home page

Tags: ConnectCriticaldefault passwordMitelMitel MiVoiceMiVoiceSecuritysecurity updatesvulnerabilities
Previous Post

The best chess, talks and artificial intelligence in the Magistral de León

Next Post

Mallorca-Valencia: the game of casualties Mallorca-Valencia

Keira Austin

Keira Austin

Related Posts

The first lensless camera arrives… thanks to AI
World

The first lensless camera arrives… thanks to AI

by Keira Austin
June 2, 2023
Roberto Brasero predicts the exact day that it will stop raining and announces that in summer "we can roast ourselves"
World

Roberto Brasero predicts the exact day that it will stop raining and announces that in summer “we can roast ourselves”

by Keira Austin
June 2, 2023
Insurers and travel agencies negotiate specific insurance for the 23J holidays
World

Insurers and travel agencies negotiate specific insurance for the 23J holidays

by Keira Austin
June 2, 2023
The United States Senate approves the agreement on the debt ceiling and avoids suspending payments
World

The United States Senate approves the agreement on the debt ceiling and avoids suspending payments

by Keira Austin
June 2, 2023
El Puente launches Combatilopram, a symbolic drug to combat stigma and promote mental health
World

El Puente launches Combatilopram, a symbolic drug to combat stigma and promote mental health

by Keira Austin
June 2, 2023
Next Post
Mallorca-Valencia: the game of casualties Mallorca-Valencia

Mallorca-Valencia: the game of casualties Mallorca-Valencia

Premium Content

A Russian deputy minister who privately criticized the 'fascist invasion' of Ukraine dies suddenly

A Russian deputy minister who privately criticized the ‘fascist invasion’ of Ukraine dies suddenly

May 22, 2023
EL PAÍS

“With the most handsome boy, come on.” ‘Ganas’, Ayuso’s song, brings TikTok into the dance of Spanish politics

May 19, 2023
AI scene is growing: Berlin start-up nyonic plans generative AI from Europe

AI scene is growing: Berlin start-up nyonic plans generative AI from Europe

May 31, 2023

Browse by Category

  • Business
  • Sports
  • World

Browse by Tags

28M Apple arrested Artificial intelligence attack Barcelona campaign ChatGPT China city data data protection day elections electoral European euros Feijóo Government great health intelligence iPhone live Madrid Microsoft million people president PSOE Real Russia Security Spain Spanish Sánchez time Valencia Vinicius vote votes Vox vulnerabilities war years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Business
  • Sports
  • World

Browse by Tag

28M Apple arrested Artificial intelligence attack Barcelona campaign ChatGPT China city data data protection day elections electoral European euros Feijóo Government great health intelligence iPhone live Madrid Microsoft million people president PSOE Real Russia Security Spain Spanish Sánchez time Valencia Vinicius vote votes Vox vulnerabilities war years

Recent Posts

  • The first lensless camera arrives… thanks to AI
  • Roberto Brasero predicts the exact day that it will stop raining and announces that in summer “we can roast ourselves”
  • Insurers and travel agencies negotiate specific insurance for the 23J holidays
  • About us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • World
  • Lifestyle
  • Business
  • Entertainment
  • Sports

© Kiratas 2023. All Rights Reserved.