LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-40765: Mitel MiVoice Connect Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 21, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 14, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-40765 to its Known Exploited Vulnerabilities catalog on Feb 21, 2023, with a federal patch deadline of Mar 14, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

CVE-2022-40765 is a command injection vulnerability in the Mitel Edge Gateway component of MiVoice Connect. An authenticated attacker who already has internal network access can execute operating-system commands in the context of the system. Because the flaw has been tied to known ransomware activity, organizations running this telephony platform should treat it as a high-priority risk that can lead to full host compromise and subsequent lateral movement.

Defenders need to confirm exact product versions and patch status against the vendor advisory, then move quickly to inventory, remediate, and monitor for signs of abuse.

How it works

The underlying weakness is CWE-77 (Improper Neutralization of Special Elements used in a Command). In this class of flaw, user-controlled input reaches a shell or command interpreter without adequate sanitization. An attacker who can authenticate and reach the Edge Gateway over the internal network supplies crafted input that the application concatenates into a system command. The injected payload then runs with the privileges of the vulnerable process, giving the attacker the ability to run arbitrary commands on the host.

No public exploit code or precise injection vector is described in the available facts; technical teams should treat any authenticated request that ultimately triggers a system call as a potential abuse path and validate behavior against the vendor’s own analysis.

Am I affected? How to find it in your systems

Mitel MiVoice Connect is typically deployed as an on-premises or hybrid voice-and-collaboration platform. The Edge Gateway component often sits at the boundary between the internal network and external SIP trunks or remote users, so it may appear on both management VLANs and voice VLANs.

Because the attacker must already be authenticated and on the internal network, focus detection efforts on lateral-movement indicators rather than purely external scanning.

How to remediate

The primary remediation is to apply the updates published by Mitel for MiVoice Connect, following the vendor’s installation instructions exactly. After patching, reboot or restart the affected services as directed and verify that the new version is reported by the management interface.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls that address the authenticated, internal-network nature of the vulnerability.

These measures buy time but do not eliminate the underlying flaw; schedule the official patch as soon as operational constraints allow.

If your data may have been exposed

Vulnerabilities that are known to be used by ransomware operators frequently lead to data theft or encryption. If you discover evidence of exploitation—or simply cannot rule it out—assume that credentials, call detail records, or configuration data may have left the environment. Rotate any secrets that resided on the affected system, review outbound traffic for exfiltration, and consider offering users a free exposure scan of their email addresses against known breach corpora so they can check whether their personal data has already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMitel · MiVoice Connect
WeaknessCWE-77
Added to CISA KEVFeb 21, 2023
Federal patch deadlineMar 14, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities