Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jan 28, 2025

CVE-2024-55550

High
EPSS 14.9%CISA KEVRansomware
Mitel/MiCollab

Description

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

EPSS — Exploit Probability

14.9%

Higher than 94.4% of all CVEs

Required Action

https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55550

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
14.9%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Jan 7, 2025

Added to KEV

Jan 7, 2025

Remediation Due

Jan 28, 2025

Affected Product

Mitel

MiCollab

View all Mitel CVEs