Impact
A flaw in the backup restoration function of Mitel MiVoice Office 400 allows an attacker who can access the backup repository to incorporate attacker-controlled files during extraction. The mechanism does not validate extraction paths, file types, integrity, or authenticity, nor does it enforce backup passwords. Because the restored files can be placed with arbitrary paths and permissions on the underlying Linux system, an attacker can overwrite privileged files or place executable binaries, potentially leading to full root compromise. The weakness relies on improper file handling and missing signature verification and is classified under CWE‑22, CWE‑434, CWE‑73, CWE‑345, and CWE‑494.
Affected Systems
Mitel MiVoice Office 400 – all releases that use the default backup restoration routine, with no version differentiation available.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and although the EPSS score is not available, the vulnerability can be exploited by anyone with read/write access to the backup repository, such as an SFTP user or another application that writes to the repository. The lack of a KEV listing does not diminish the risk, as the attack requires no special conditions. Attacks are feasible via a crafted TGZ archive and can result in arbitrary code execution with system privileges.
OpenCVE Enrichment