Mitel is the market leader in unified communications. Mitel MiVoice Office 400 to version R7.2 SP1, running Linux Release 11.0.96.0, does not implement Secure Boot, UEFI Secure Boot, boot/filesystem integrity protection, or LUKS disk encryption.
A malicious person or an attacker with access to the VMDK could therefore modify the virtual disk offline and inject persistent malicious code without being detected. Such code could execute automatically at system startup or when specific application features are triggered, allowing persistence across reboots, since there's no integrity check on system files. This exposes the solution to offline disk tampering, persistent code injection, boot-chain compromise, and lack of integrity verification. The absence of these controls significantly weakens the appliance's trust model and protection against persistent compromise.
- 04.08.2026
DigitalCanion asks the vendor for a PGP key to submit the flaw.
- 06.08.2026
DigitalCanion submits the issue to the vendor.
- 06.08.2026
Mitel acknowledges the submission and starts its investigation.
- 14.08.2026
DigitalCanion asks the vendor for an update.
- 16.08.2026
No news from Mitel. DigitalCanion asks the vendor again for an update.
- 17.08.2026
Mitel claims the issue is addressed in the latest MSL release and redirects us to an upgrade/support channel without directly addressing the reported vulnerability.
- 17.08.2026
As a workaround, Mitel suggested upgrading MiVoice Office 400 to R7.2 SP1. However, this would be a completely new installation rather than a patch for Release 7.1 SP2 HF2. DigitalCanion emphasised that R7.1 SP2 HF2 is widely deployed worldwide and that Mitel keeps actively selling licences for it, so it would be reasonable to expect Mitel to help maintain the security of customers still relying on this supported version.
- 17.08.2026
Mitel answers that they are reviewing the issue with the appropriate Product Management teams and asks for some time.
- 19.08.2026
DigitalCanion asks for an update on the issue.
- 21.08.2026
Mitel says this is not a vulnerability for them and acknowledges that their Mitel VMware solution has no UEFI Secure Boot or any other mechanism to prevent tampering with their solution.
- 24.08.2026
DigitalCanion explains that this is not a serious answer and gives Mitel one more opportunity to take action.
- 28.08.2026
Mitel answers that their assessment was provided on 21-Aug-2026 and decides to do nothing on this issue.
- 29.08.2026
DigitalCanion informs Mitel of its intention to publish the case as a 0-day advisory, including a proof-of-concept video.