« Back to list

CVE-2025-67822

Status: AnalyzedCritical (9.4)—

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized access to user or admin accounts in the system.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:N/PR:N sin interacción indica explotación remota sin autenticación (T1190). CWE-287 y descripción de bypass autenticación confirman acceso a cuentas de usuario/admin (T1078), con posible manipulación de cuentas (T1098).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-67822",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-67822",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-16T14:55:43.213583Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.4,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-01-15T22:16:10.990",
  "references": [
    {
      "url": "https://www.mitel.com/support/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized access to user or admin accounts in the system."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en el componente Provisioning Manager de Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) hasta 7.8 SP1 (7.8.1.0.14) podría permitir a un atacante no autenticado realizar un ataque de omisión de autenticación debido a mecanismos de autenticación inadecuados. Un exploit exitoso podría permitir a un atacante obtener acceso no autorizado a cuentas de usuario o de administrador en el sistema."
    }
  ],
  "lastModified": "2026-06-17T09:58:08.413",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mitel:mivoice_mx-one:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D6F15CE-2EBD-46A7-B8B0-1FBAD696DFC3",
              "versionEndExcluding": "7.8",
              "versionStartIncluding": "7.3"
            },
            {
              "criteria": "cpe:2.3:a:mitel:mivoice_mx-one:7.8:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4639F33-2298-4E24-8799-15A35184C517"
            },
            {
              "criteria": "cpe:2.3:a:mitel:mivoice_mx-one:7.8:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C74A8524-BE0F-49D4-BAAF-BB7856503D16"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}