CVE-2022-29499
Mitel MiVoice Connect Service Appliances (SA 100, SA 400, Virtual SA) through version 19.2 SP3 are vulnerable to remote code execution due to improper data validation. An attacker can run arbitrary code without authentication or user interaction. The vulnerability is critical with a CVSS score of 9.8.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Mitel MiVoice Connect Service Appliances (SA 100, SA 400, Virtual SA) running version 19.2 SP3 or earlier.
Real-world impact
An attacker could take full control of the affected Service Appliance, potentially compromising the entire VoIP infrastructure, data, and network.
Why this severity
The CVSS score of 9.8 reflects that the flaw allows remote code execution with no authentication, no user interaction, and full impact on confidentiality, integrity, and availability.
What to do about it
- 01Follow Mitel’s instructions to update the Service Appliance component to a patched version.
CISA KEV required action
Timeline
- Apr 26, 2022 · Apr 26, 2022PublishedDisclosed and added to the National Vulnerability Database.
- Jun 27, 2022 · Jun 27, 2022Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 18, 2022 · Jul 18, 2022CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 6, 2026 · 3h agoAdvisory updatedThe NVD record was last revised.
- Aug 6, 2026 · 54m agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- mitel.com/support/security-advisories…vendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource