CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-47223

CVSS 9.4v3.1pub. 2024-10-21upd. 2025-07-07

A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access non-sensitive user provisioning information and execute arbitrary SQL database commands.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation (sanitization) of user-supplied input data in the AWV component. An attacker can submit a specially crafted network request containing malicious SQL fragments, which will be passed directly to the database without proper sanitization. No authentication or user interaction is required.

Impact

An attacker can gain access to user provisioning information and execute arbitrary commands in the SQL database, which may lead to data integrity violations and system availability disruption.

Mitigation & patch

Apply patches available from the vendor according to the references — details in Mitel security advisory MISA-2024-0028 available at: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0028

Who is affected

Mitel MiCollab versions up to and including 9.8 SP1 FP2 (9.8.1.201) — AWV (Audio, Web and Video Conferencing) component.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Mitel Micollab

    APP
    Mitel
    ≤ 9.8.1.201
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2024-41713CRITICAL9.1⚠ KEVPL ✓same product

Path Traversal w Mitel MiCollab — nieautoryzowany dostęp do danych

CVE-2022-26143CRITICAL9.8⚠ KEVPL ✓same product

Mitel MiCollab/MiVoice TP-240: wyciek danych i DDoS amplifikacja

CVE-2024-35286CRITICAL9.8PL ✓same product

SQL Injection w Mitel MiCollab NuPoint Messenger — dostęp bez uwierzytelnienia

CVE-2024-35285CRITICAL9.8PL ✓same product

Command injection w Mitel MiCollab NuPoint Messenger — dostęp bez uwierzytelnienia

CVE-2024-35314CRITICAL9.8PL ✓same product

Command Injection w Mitel MiCollab i MiVoice Business Solution Virtual Instance