Impact
A flaw in the Music on Hold functionality of Mitel MiVoice Office 400 allows a remote attacker to upload a malicious shared object file that is accepted as a WAV file, causing the backend to load and execute attacker‑controlled code within the service process and ultimately compromising the Linux system.
Affected Systems
Any installation of Mitel MiVoice Office 400, specifically the Music on Hold service exposed via the web portal on TCP port 443. No specific version numbers are listed in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 8.4, indicating high severity, and there is no EPSS data or KEV listing. Authentication to the web portal is required, so the breach is not fully anonymous; once authentication is obtained, the attacker can achieve remote code execution. The likely attack vector is via the HTTPS interface for uploading media files, though the exact path is inferred from the description.
OpenCVE Enrichment