CVE-2024-35286
moderateUnauthenticated SQL Injection in Mitel MiCollab NuPoint Messenger (CVE-2024-35286)
CVE-2024-35286 is a critical, unauthenticated SQL injection flaw (CWE-89) in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8.0.33, caused by insufficient sanitization of user-supplied input. A remote attacker can trigger it directly over the network with no credentials, no privileges, and no user interaction (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N). A successful exploit allows the attacker to access sensitive information and execute arbitrary database and management operations, which in practice can mean reading or altering voicemail/directory data and performing administrative actions on the NPM system. Any organization running MiCollab 9.8.0.33 or earlier with the NuPoint Messenger component is affected. This CVE is not yet on CISA's KEV and no public PoC is cataloged for it, but its EPSS of 65.7% (99th percentile) indicates a high probability of exploitation within 30 days, and related Mitel MiCollab flaws are reported as under active exploitation.
What to do: Upgrade MiCollab to a patched release beyond 9.8.0.33 per Mitel's security advisory, and until then restrict the NuPoint Messenger web interface to trusted networks only (firewall/ACL) or apply WAF/SQL-injection filtering on NPM endpoints. Review NPM and database logs for anomalous or crafted queries and any unexpected database or management changes. Given the 65.7% EPSS, prioritize patching and monitor for this CVE's addition to CISA KEV.
| Mitel MiCollab - NuPoint Messenger (NPM) component | through 9.8.0.33 (all versions up to and including 9.8.0.33) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
- Vendors
- mitel
- Products
- micollab
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H