Cyber Resilience

CVE-2023-39291

Mitel Mivoice Connect ≤ 9.6.2304.102

Published
25 August 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 4.9
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0046 38th percentile
Risk Priority 39 floored blend · peak EPSS

Summary

CVE-2023-39291 is a medium-severity an unspecified weakness vulnerability in Mitel Mivoice Connect. Its CVSS base score is 4.9 (Medium).

Operationally, ranked at the 38th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view…

more

system information.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-39285Same product: Mitel Mivoice Connect
CVE-2023-39288Same product: Mitel Mivoice Connect
CVE-2023-39289Same product: Mitel Mivoice Connect
CVE-2023-31458Same product: Mitel Mivoice Connect
CVE-2023-31460Same product: Mitel Mivoice Connect
CVE-2023-25598Same product: Mitel Mivoice Connect
CVE-2022-41223Same product: Mitel Mivoice Connect
CVE-2023-31459Same product: Mitel Mivoice Connect
CVE-2022-40765Same product: Mitel Mivoice Connect
CVE-2023-39287Same product: Mitel Mivoice Connect

Affected Assets

mitel
mivoice connect
≤ 9.6.2304.102

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References