CVE-2024-55550 - Mitel MiCollab
AI Vulnerability ContextMitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modifica...
Overview
A source-backed snapshot of this vulnerability.
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2024-55550
- Vendor/project
- Mitel
- Product
- MiCollab
- Vulnerability name
- Mitel MiCollab Path Traversal Vulnerability
- Date added
- 2025-01-07
- Due date
- 2025-01-28
- Known ransomware campaign use
- Known
- CVSS v3
- 2.7
Exploit context
What the vulnerability is about.
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
