S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 26, 2025

CVE-2022-29499 Scanner

CVE-2022-29499 Scanner - Remote Code Execution (RCE) vulnerability in Mitel MiVoice Connect

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
5.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-29499
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Mitel MiVoice Connect is a telephony solution designed for businesses to facilitate communication through an IP-based phone system. It is used widely in enterprises that require a stable and efficient voice communication system. The product offers features such as voice calling, voicemail, conferencing, and instant messaging. This Mitel solution integrates well with various communication networks and is often utilized in corporate environments. Continuously updated to ensure security, Mitel MiVoice Connect aims to provide reliable service across diverse organizational structures. The platform supports integration with both on-premises and cloud environments for flexible deployment.

The vulnerability found in Mitel MiVoice Connect is a Remote Code Execution (RCE) issue that arises due to improper data validation. Such vulnerabilities allow unauthorized attackers to execute arbitrary code on susceptible systems. This specific flaw affects the Service Appliances component within the Mitel MiVoice Connect product suite. Exploiting this vulnerability can give attackers control over affected appliances, posing significant risks. When left unpatched, RCE vulnerabilities can severely compromise system integrity and data security. Addressing these vulnerabilities promptly is crucial to maintaining enterprise communication security.

The vulnerability details show that the Service Appliance component does not properly validate incoming data, allowing attackers to manipulate system processes. This misconfiguration provides an entry point for executing arbitrary code. The endpoint or parameter that is vulnerable is associated with the handling of data requests in the Service Appliances. Specific appliances affected include the SA 100, SA 400, and Virtual SA, which are key components of the Mitel MiVoice Connect service infrastructure. Attackers exploit this by sending crafted requests to vulnerable endpoints. These actions bypass standard security protocols, leading to unauthorized command execution.

Exploitation of this vulnerability can lead to severe consequences, including unauthorized access to sensitive information and disruption of communication services. Attackers can use the RCE flaw to take control of the underlying system, potentially leading to data breaches or system compromises. This could result in significant operational disruptions, particularly in environments where voice communication is critical. Moreover, there is the possibility of installing malware or other malicious services, further threatening network security. Ultimately, the impact of such exploitation could extend to financial losses and damage to organizational reputation.

REFERENCES

Solution Advice
  • Ensure the Mitel MiVoice Connect system is updated to the latest version to incorporate any patches provided by Mitel.
  • Implement stringent input validation procedures to prevent unauthorized code execution.
  • Regularly audit and monitor network traffic for any unusual or suspicious activities.
  • Ensure that the communication systems are isolated from the main network to contain any potential breaches.
  • Conduct periodic security assessments to identify and mitigate potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-29499 Scanner - Remote Code Execution (RCE) vulnerability in Mitel MiVoice Connect | S4E