CVE-2023-31457: Mitel MiVoice Connect

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

Affected products

  • Mitel MiVoice Connect: up to and including 22.24.1500.0

Published 2023-05-24. Last modified 2026-06-17.