CVE-2024-41713
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
CISA KEV
- Vendor
- Mitel
- Product
- MiCollab
- Due date
- 2025-01-28
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-41713
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.