
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical path traversal vulnerability (CVE-2024-41713) was discovered in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through version 9.8 SP1 FP2 (9.8.1.201). The vulnerability allows an unauthenticated attacker to conduct a path traversal attack due to insufficient input validation. This vulnerability was discovered by Sonny Macdonald of watchTowr and was later added to CISA's Known Exploited Vulnerabilities Catalog on January 7, 2025 (Mitel Advisory, CISA Alert).
The vulnerability exists in the NuPoint Unified Messaging (NPM) component and can be exploited through the /npm-pwg/..;/usp/ endpoint. The flaw received a CVSS 3.1 base score of 9.8 (Critical), with the vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability stems from insufficient input validation in the path traversal mechanism, allowing attackers to bypass authentication and access restricted system resources (Mitel Advisory, WatchTowr Labs).
If successfully exploited, the vulnerability allows unauthorized access to the system, enabling attackers to view, corrupt, or delete users' data and system configurations. Attackers can gain unauthenticated access to provisioning information including non-sensitive user and network information and perform unauthorized administrative actions on the MiCollab Server (Mitel Advisory).
The vulnerability is actively being exploited in the wild, as evidenced by its addition to CISA's Known Exploited Vulnerabilities Catalog. A proof-of-concept exploit has been publicly released by watchTowr Labs, demonstrating the vulnerability's exploitation through path traversal techniques (WatchTowr Labs, CISA Alert).
Mitel has released version 9.8 SP2 (9.8.2.12) which patches this vulnerability. For customers unable to upgrade immediately, Mitel has provided a patch that is available for releases 6.0 and above, which is compatible with MiVB-x. Detailed instructions for both the upgrade and patch installation can be found in Mitel's Knowledge Base article SO8219 (Mitel Advisory).
The vulnerability has gained significant attention in the cybersecurity community, with approximately 8,899 to 16,000 exposed Mitel MiCollab instances identified globally. According to Censys research, 54% of the exposed instances are located in the United States (Censys Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."