Known vulnerabilities in MiVoice Business Solution Virtual Instance (MiVB SVI)

Vendor: Mitel
Software CPE: cpe:2.3:a:mitel:mivoice_business_solution_virtual_instance_mivb_svi:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting MiVoice Business Solution Virtual Instance (MiVB SVI) MiVoice Business Solution Virtual Instance (MiVB SVI) is affected by 15 known vulnerabilities: 13 high, 1 medium, 1 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134866 - Improper Certificate Validation
CWE-295 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134867 - Command injection
CWE-77 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134868 - Command injection
CWE-77 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134869 - Missing Authentication for Critical Function
CWE-306 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134870 - Server-Side Request Forgery (SSRF)
CWE-918 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134871 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134872 - Command injection
CWE-77 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134873 - Command injection
CWE-77 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134874 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134875 - Unrestricted Upload of File with Dangerous Type
CWE-434 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134876 - Improper Restriction of XML External Entity Reference ('XXE')
CWE-611 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU134877 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE-89 High
No
No
2.1.0.9-4 18.06.2026 SB2026061848
#VU94731 - Command injection
CVE-2024-41714
CWE-77 Medium
No
No
- 25.07.2024 SB2024072517
#VU90709 - Permissions, Privileges, and Access Controls
CVE-2024-35315
CWE-264 Low
Available
No
- 03.06.2024 SB2024060312
#VU90707 - Argument Injection or Modification
CVE-2024-35314
CWE-88 High
No
No
- 03.06.2024 SB2024060312