Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jan 28, 2025

High
CISA KEVRansomware

CVE-2024-55550

MitelMiCollab

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

Required Action

https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55550

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Known
Published
Jan 7, 2025
KEV Added
Jan 7, 2025
Due Date
Jan 28, 2025
Related Articles
0

Vendor

Mitel

MiCollab