The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
References
| Link | Resource |
|---|---|
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 | Vendor Advisory |
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499 | US Government Resource |
Configurations
History
03 Nov 2025, 17:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499 - US Government Resource |
22 Oct 2025, 00:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 06:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002 - Vendor Advisory |
Information
Published : 2022-04-26 02:15
Updated : 2025-11-03 17:39
NVD link : CVE-2022-29499
Mitre link : CVE-2022-29499
CVE.ORG link : CVE-2022-29499
JSON object : View
Products Affected
mitel
- mivoice_connect
CWE
CWE-20
Improper Input Validation
