A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
The vulnerability stems from insufficient input validation in the NPM component of the Mitel MiCollab system. An unauthenticated attacker can send crafted requests containing path traversal sequences (e.g., '../'), which allow breaking out of the permitted directory and accessing arbitrary files or system resources. Due to the lack of user interaction and authentication requirements, the attack can be conducted remotely over the network.
A successful attack allows an unauthorized attacker to view, modify, or delete user data and system configurations. This can lead to serious violations of confidentiality and integrity of data processed by the system.
Apply patches available from the vendor according to references — details in the Mitel security message MISA-2024-0029 available at https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029
Mitel MiCollab in versions up to and including 9.8 SP1 FP2 (9.8.1.201)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMitel Micollab
APPMitel≤ 9.8.1.201
CISA KEV — detailsi
- Vendori
- Mitel
- Producti
- MiCollab
- Added to KEVi
- January 7, 2025
- Remediation deadline (US Federal)i
- January 28, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Related vulnerabilities
Mitel MiCollab/MiVoice TP-240: wyciek danych i DDoS amplifikacja
SQL Injection w Mitel MiCollab NuPoint Messenger — dostęp bez uwierzytelnienia
Command injection w Mitel MiCollab NuPoint Messenger — dostęp bez uwierzytelnienia
Command Injection w Mitel MiCollab i MiVoice Business Solution Virtual Instance
SQL Injection w komponencie AWV Mitel MiCollab — dostęp bez uwierzytelnienia