cve-2022-29499
CRITICAL CVSS 9.8 opencve
Description
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
Timeline
- Published
- 2022-04-26 02:15 UTC
- Last Modified
- 2026-08-06
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
nvd | ||
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
opencve | ||
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
vulnrichment |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2022-29499",
"epss": {
"score": 0.54317
},
"kev": {
"dateAdded": "2022-06-27T00:00:00+00:00",
"dueDate": "2022-07-18T00:00:00+00:00"
},
"mitre": {
"cpes": [],
"created": "2022-04-26T01:13:58+00:00",
"description": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2022/29xxx/CVE-2022-29499.json",
"references": [
"https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002"
],
"title": null,
"updated": "2026-08-06T03:55:35.248000+00:00",
"vendors": [],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:mitel:mivoice_connect:*:*:*:*:*:*:*:*"
],
"created": "2022-04-26T02:15:37.107000+00:00",
"description": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.",
"metrics": {
"cvssV2_0": {
"score": 10.0,
"vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
},
"cvssV3_0": {},
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2022/CVE-2022-29499.json",
"references": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499",
"https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002"
],
"title": null,
"updated": "2026-08-06T05:16:37.230000+00:00",
"vendors": [
"mitel",
"mitel$PRODUCT$mivoice_connect"
],
"weaknesses": [
"CWE-20"
]
},
"opencve": {
"changes": [
{
"created": "2025-01-29T17:15:00+00:00",
"data": [
{
"details": {
"added": {
"kev": {
"dateAdded": "2022-06-27"
},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "e9687177-e451-4637-8986-52c78b4ac6ff"
},
{
"created": "2025-10-21T19:30:00+00:00",
"data": [
{
"details": {
"added": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499"
],
"removed": []
},
"type": "references"
}
],
"id": "f678e783-443d-42d1-8201-8e39ee4d3a8d"
},
{
"created": "2025-10-21T20:30:00+00:00",
"data": [
{
"details": {
"added": [],
"removed": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499"
]
},
"type": "references"
}
],
"id": "531f256a-85c7-426c-9cc6-07b56ea08727"
},
{
"created": "2025-10-22T00:15:00+00:00",
"data": [
{
"details": {
"added": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499"
],
"removed": []
},
"type": "references"
}
],
"id": "123f45b1-714d-4830-aefe-e433813088d8"
}
],
"cpes": {
"data": [
"cpe:2.3:a:mitel:mivoice_connect:*:*:*:*:*:*:*:*"
],
"providers": [
"nvd"
]
},
"created": {
"data": "2022-04-26T01:13:58+00:00",
"provider": "mitre"
},
"description": {
"data": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {
"score": 10.0,
"vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
},
"provider": "nvd"
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"provider": "vulnrichment"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.54317
},
"provider": "first"
},
"kev": {
"data": {
"dateAdded": "2022-06-27T00:00:00+00:00",
"dueDate": "2022-07-18T00:00:00+00:00"
},
"provider": "cisa"
},
"ssvc": {
"data": {
"options": {
"Automatable": "yes",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499",
"https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0002"
],
"providers": [
"mitre",
"nvd",
"vulnrichment"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2025-11-03T17:39:18.517000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"mitel",
"mitel$PRODUCT$mivoice_connect"
],
"providers": [
"nvd"
]
},
"weaknesses": {
"data": [
"CWE-20"
],
"providers": [
"nvd",
"vulnrichment"
]
}
},
"vulnrichment": {
"cpes": [],
"created": "2022-04-26T01:13:58+00:00",
"description": "The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 9.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvssV4_0": {},
"kev": {
"dateAdded": "2022-06-27"
},
"ssvc": {
"options": {
"Automatable": "yes",
"Exploitation": "active",
"Technical Impact": "total"
},
"version": "2.0.3"
}
},
"references": [
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29499"
],
"title": null,
"updated": "2025-01-29T16:10:44.510000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2022/29xxx/CVE-2022-29499.json",
"weaknesses": [
"CWE-20"
]
}
}
Enrichment data
Aggregated bundle (all enrichments)