CVE-2023-39285: Mitel MiVoice Connect
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.
Affected products
- Mitel MiVoice Connect: before 22.24.7100.0 (fixed in 22.24.7100.0)
Published 2023-09-14. Last modified 2026-06-17.