CVE-2024-55550
Mitel MiCollab Path Traversal Vulnerability
CVSS
2.7
Low
EPSS
37.8%
p98
KEV
YES
Jan 7, 2025
Exploit Today
80
0-100
Published: Dec 10, 2024 · Last modified: Aug 4, 2026 · CWE-22
Product
Mitel / MiCollab
Vulnerability
Mitel MiCollab Path Traversal Vulnerability
Added to KEV
Jan 7, 2025
Remediate by
Jan 28, 2025
Known ransomware use
Yes
Summary description
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55550
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.