Junglewise Threat Intelligence

CVE-2024-55550: Mitel MiCollab Path Traversal Vulnerability

CVE-2024-55550 · Severity: critical · CVSS 4.4 · Exploited in the wild · Published 2025-01-07

Technologies: Mitel MiCollab, Mitel MiVoice Business Express. Vendors: Mitel.

Executive brief

Mitel MiCollab contains a path traversal vulnerability due to insufficient input sanitization. An authenticated attacker with administrative privileges can exploit this to read local files, potentially accessing non-sensitive system information or resources constrained to the admin level.

Affected products

  • Mitel MiCollab through 9.8 SP2 (up to and including 9.8.1.201)

Timeline

  • 2024-12-10: disclosed: Initial NVD publication and vendor advisory release.
  • 2025-01-07: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2025-01-07: exploited: Confirmed as exploited in the wild by CISA.

Related threats