ZeroHour

CVE-2024-35286

moderate

Unauthenticated SQL Injection in Mitel MiCollab NuPoint Messenger (CVE-2024-35286)

CVSS 3.1
9.8 critical
EPSS
66%p99
Published
()
Modified
AI analysis

CVE-2024-35286 is a critical, unauthenticated SQL injection flaw (CWE-89) in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8.0.33, caused by insufficient sanitization of user-supplied input. A remote attacker can trigger it directly over the network with no credentials, no privileges, and no user interaction (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N). A successful exploit allows the attacker to access sensitive information and execute arbitrary database and management operations, which in practice can mean reading or altering voicemail/directory data and performing administrative actions on the NPM system. Any organization running MiCollab 9.8.0.33 or earlier with the NuPoint Messenger component is affected. This CVE is not yet on CISA's KEV and no public PoC is cataloged for it, but its EPSS of 65.7% (99th percentile) indicates a high probability of exploitation within 30 days, and related Mitel MiCollab flaws are reported as under active exploitation.

What to do: Upgrade MiCollab to a patched release beyond 9.8.0.33 per Mitel's security advisory, and until then restrict the NuPoint Messenger web interface to trusted networks only (firewall/ACL) or apply WAF/SQL-injection filtering on NPM endpoints. Review NPM and database logs for anomalous or crafted queries and any unexpected database or management changes. Given the 65.7% EPSS, prioritize patching and monitor for this CVE's addition to CISA KEV.

Affected
Mitel MiCollab - NuPoint Messenger (NPM) componentthrough 9.8.0.33 (all versions up to and including 9.8.0.33)
Estimated exposure
moderate≈ low thousands of internet-exposed MiCollab/NuPoint Messenger systems (public scans), with the broader enterprise installed base plausibly in the low tens of… — Public internet-exposure scans of MiCollab/NuPoint Messenger web consoles index only a few thousand hosts, and this flaw additionally requires the NPM component, while Mitel's total enterprise UC footprint is considerably larger but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.

Vendors
mitel
Products
micollab
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news