June 27, 2022 · Applied Cybernetics Group
CVE-2022-29499 — Mitel MiVoice Connect
known ransomware use
Mitel MiVoice Connect Data Validation Vulnerability
- Added to KEV
2022-06-27- Federal due date
2022-07-18- Vendor
- Mitel
- Product
- MiVoice Connect
- EPSS
- 99.0th percentile (score 0.556, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-29499
CISA short description
The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
Required action
Apply updates per vendor instructions.
NVD description
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.