CVE-2024-41713
Mitel MiCollab vulnerability analysis and mitigation

Overview

A critical path traversal vulnerability (CVE-2024-41713) was discovered in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through version 9.8 SP1 FP2 (9.8.1.201). The vulnerability allows an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. This vulnerability was discovered by Sonny Macdonald of watchTowr and was later added to CISA's Known Exploited Vulnerabilities Catalog on January 7, 2025 (Mitel Advisory, CISA Alert).

Technical details

The vulnerability exists in the NuPoint Unified Messaging (NPM) component and can be exploited through the /npm-pwg/..;/usp/ endpoint. The flaw received a CVSS 3.1 base score of 9.8 (Critical), with the vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability stems from insufficient input validation in the path traversal mechanism, allowing attackers to bypass authentication and access restricted system resources (Mitel Advisory, WatchTowr Labs).

Impact

If successfully exploited, the vulnerability allows unauthorized access to the system, enabling attackers to view, corrupt, or delete users' data and system configurations. Attackers can gain unauthenticated access to provisioning information including non-sensitive user and network information and perform unauthorized administrative actions on the MiCollab Server (Mitel Advisory).

Exploitability

The vulnerability is actively being exploited in the wild, as evidenced by its addition to CISA's Known Exploited Vulnerabilities Catalog. A proof-of-concept exploit has been publicly released by watchTowr Labs, demonstrating the vulnerability's exploitation through path traversal techniques (WatchTowr Labs, CISA Alert).

Mitigation and workarounds

Mitel has released version 9.8 SP2 (9.8.2.12) which patches this vulnerability. For customers unable to upgrade immediately, Mitel has provided a patch that is available for releases 6.0 and above, which is compatible with MiVB-x. Detailed instructions for both the upgrade and patch installation can be found in Mitel's Knowledge Base article SO8219 (Mitel Advisory).

Community reactions

The vulnerability has gained significant attention in the cybersecurity community, with approximately 8,899 to 16,000 exposed Mitel MiCollab instances identified globally. According to Censys research, 54% of the exposed instances are located in the United States (Censys Report).

Additional resources


SourceThis report was generated using AI

Related Mitel MiCollab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-41713CRITICAL9.1
  • Mitel MiCollab logoMitel MiCollab
  • cpe:2.3:a:mitel:micollab
YesYesOct 21, 2024
CVE-2025-52914HIGH8.8
  • Mitel MiCollab logoMitel MiCollab
  • cpe:2.3:a:mitel:micollab
NoYesAug 08, 2025
CVE-2024-41714HIGH8.8
  • Mitel MiCollab logoMitel MiCollab
  • cpe:2.3:a:mitel:micollab
NoYesOct 21, 2024
CVE-2024-47224MEDIUM6.5
  • Mitel MiCollab logoMitel MiCollab
  • cpe:2.3:a:mitel:micollab
NoYesOct 21, 2024
CVE-2024-55550LOW2.7
  • Mitel MiCollab logoMitel MiCollab
  • cpe:2.3:a:mitel:micollab
YesYesDec 10, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management