CVE-2024-55550
Mitel MiCollab Path Traversal Vulnerability
CVSS
2.7
Bajo
EPSS
37.8%
p98
KEV
SÍ
7 ene 2025
Exploit Today
80
0-100
Publicado: 10 dic 2024 · Última mod.: 4 ago 2026 · CWE-22
Producto
Mitel / MiCollab
Vulnerabilidad
Mitel MiCollab Path Traversal Vulnerability
Añadido a KEV
7 ene 2025
Remediar antes de
28 ene 2025
Uso conocido en ransomware
Sí
Descripción resumida
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Acción requerida
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notas
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55550
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.