LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-29499: Mitel MiVoice Connect Data Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 27, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-29499 to its Known Exploited Vulnerabilities catalog on Jun 27, 2022, with a federal patch deadline of Jul 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.

CVE-2022-29499 is a data validation flaw in the Service Appliance component of Mitel MiVoice Connect that can allow remote code execution. Incorrect handling of input lets an attacker reach code execution on the appliance, which sits in the voice and collaboration path for many organizations. CISA has noted known ransomware use of this vulnerability, so unpatched systems should be treated as high priority for inventory and remediation. Confirm all product, version, and fix details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In plain terms, the Service Appliance does not adequately check or constrain data it receives before acting on it. When validation is incomplete, crafted input can influence program flow or command execution on the appliance itself.

An attacker who can reach the affected component over the network may send specially formed requests that bypass the intended checks. Successful abuse can result in remote code execution under the privileges of the vulnerable service. Exact request formats, required access level, and preconditions are not detailed here; treat any internet- or WAN-facing MiVoice Connect Service Appliance as potentially reachable and verify the precise attack surface in the vendor advisory and your own network diagrams.

Am I affected? How to find it in your systems

Mitel MiVoice Connect is an on-premises or hybrid voice/UC platform. The Service Appliance is a discrete component often deployed alongside call-control and media elements. It commonly appears in enterprise voice environments, contact centers, and branch or data-center footprints that still run Mitel Connect.

If you cannot positively identify the component or its patch level, assume it may be affected until the vendor advisory and local evidence say otherwise.

How to remediate

Patch first. Apply the updates Mitel released for this vulnerability, following the vendor’s installation and verification steps exactly. CISA’s required action is to apply updates per vendor instructions; schedule the work promptly, especially where ransomware use has been observed in the wild.

If you can't patch immediately

Use compensating controls to shrink the attack surface until the vendor update can be applied.

These steps reduce risk but do not replace the patch. Track the exception and remediate on a short deadline.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to broader compromise and data theft. If you have evidence of exploitation or cannot rule it out, follow your incident-response plan: isolate affected systems, preserve logs and disk images, and engage forensics as needed. Rotate credentials that may have been present on or accessible from the appliance, and review voice, voicemail, and related stores for unauthorized access. You can also run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials or personal data have appeared in prior incidents, then force password resets and enable stronger authentication where exposures are found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMitel · MiVoice Connect
WeaknessCWE-20
Added to CISA KEVJun 27, 2022
Federal patch deadlineJul 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities