CVE-2023-22854: Mitel Micontact Center Business

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary files, due to insufficient restriction of URL parameters. A successful exploit could allow access to sensitive information.

Affected products

  • Mitel Micontact Center Business: from 9.2.2.0, before 9.4.2.0 (fixed in 9.4.2.0)

Published 2023-02-13. Last modified 2026-06-17.