CVE-2024-55550 is a path traversal vulnerability in Mitel MiCollab through version 9.8 SP2, allowing authenticated administrators to perform local file reads due to insufficient input sanitization. The CVSS score is 2.7 (LOW), indicating a network-based attack requiring high privileges with low impact, limited to non-sensitive system information disclosure without file modification or privilege escalation. Despite the low CVSS score, this CVE is actively exploited, listed in CISA's KEV catalog, and has high community discussion and media coverage, with Nuclei templates available for critical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.8.1.201CPE matchmatch criteria | cpe:2.3:a:mitel:micollab:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.