CVE Vulnerabilities

CVE-2025-67822

Improper Authentication

Published: Jan 15, 2026 | Modified: Jan 21, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized access to user or admin accounts in the system.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Mivoice_mx-oneMitel7.3 (including)7.8 (excluding)
Mivoice_mx-oneMitel7.8 (including)7.8 (including)
Mivoice_mx-oneMitel7.8-sp1 (including)7.8-sp1 (including)

Potential Mitigations

References