ZeroHour

CVE-2024-41713

KEV ransomwarelarge1

Unauthenticated Path Traversal in Mitel MiCollab NuPoint Unified Messaging

CISA: Mitel MiCollab Path Traversal Vulnerability

CVSS 3.1
9.1 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

CVE-2024-41713 is a path traversal vulnerability (CWE-22) in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201), caused by insufficient input validation. An unauthenticated remote attacker can send crafted requests that traverse the file system without needing credentials or user interaction. A successful exploit grants unauthorized access allowing the attacker to view, corrupt, or delete users' data and system configurations, and reporting indicates exposure to unauthorized file and administrative access. Any organization running an affected MiCollab version, particularly with the NPM component reachable from untrusted networks, is at risk. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, and EPSS places it in the top percentile with a 98.1% probability of exploitation within 30 days.

What to do: Upgrade MiCollab to a release later than 9.8 SP1 FP2 (9.8.1.201) per Mitel's advisory; if patching is not immediately possible, apply the vendor's mitigations or restrict/discontinue use of the NPM component, especially where it is internet-facing, as required by the CISA KEV entry. Given known ransomware use and reported admin-access abuse, hunt for signs of exploitation on exposed MiCollab servers (unexpected file changes, configuration tampering, and follow-on lateral movement).

Affected
Mitel MiCollab (NuPoint Unified Messaging component)through 9.8 SP1 FP2 (9.8.1.201)
Estimated exposure
largeon the order of tens of thousands of enterprise deployments, with thousands of MiCollab instances likely internet-exposed — MiCollab is a widely deployed enterprise unified-communications platform and public internet scans of Mitel UC products routinely show thousands of exposed instances, implying an exposed base in the 10k-100k range across all deployments.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CISA Known Exploited Vulnerability
Affected
Mitel MiCollab
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
mitel
Products
micollab
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news