Executive brief
Mitel MiCollab contains a path traversal vulnerability due to insufficient input sanitization. An authenticated attacker with administrative privileges can exploit this to read local files, potentially accessing non-sensitive system information or resources constrained to the admin level.
Affected products
- Mitel MiCollab through 9.8 SP2 (up to and including 9.8.1.201)
Timeline
- 2024-12-10: disclosed: Initial NVD publication and vendor advisory release.
- 2025-01-07: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2025-01-07: exploited: Confirmed as exploited in the wild by CISA.