Executive brief
A path traversal vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab allows unauthenticated remote attackers to bypass input validation. Successful exploitation enables unauthorized access to view, corrupt, or delete user data and system configurations, and can be chained with other vulnerabilities for arbitrary file reads.
Affected products
- Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201)
Timeline
- 2024-10-21: disclosed: NVD Published Date
- 2025-01-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog