CVE-2024-41713 is a critical path traversal vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through version 9.8 SP1 FP2, allowing unauthenticated attackers to gain unauthorized access and potentially view, corrupt, or delete user data and system configurations. With a CVSS score of 9.1 (CRITICAL) and an EPSS score indicating high exploitability, this flaw is easily exploitable over the network without user interaction. The vulnerability is actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community discussion and media coverage, with Nuclei templates available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.8.1.201CPE matchmatch criteria | cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MiCollab Path Traversal Vulnerability
Oct 9, 2024MiCollab Path Traversal Vulnerability
Oct 9, 2024MiCollab Path Traversal Vulnerability
Oct 9, 2024MiCollab Path Traversal Vulnerability
Oct 9, 2024MiCollab Path Traversal Vulnerability
Oct 9, 2024