CVE-2024-41713
Mitel MiCollab Path Traversal Vulnerability
CVSS
9.1
Crítico
EPSS
98.1%
p100
KEV
SÍ
7 ene 2025
Exploit Today
80
0-100
Publicado: 21 oct 2024 · Última mod.: 4 ago 2026 · CWE-22
Producto
Mitel / MiCollab
Vulnerabilidad
Mitel MiCollab Path Traversal Vulnerability
Añadido a KEV
7 ene 2025
Remediar antes de
28 ene 2025
Uso conocido en ransomware
Sí
Descripción resumida
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Acción requerida
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notas
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-41713
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.