Vulnerability record · CVE-2024-35286 · published 21 October 2024
CVE-2024-35286: Mitel MiCollab NuPoint Messenger unauthenticated SQL injection
Mitel · Micollab
NuPoint Messenger in Mitel MiCollab through 9.8.0.33 fails to sanitize user input, allowing SQL injection. An unauthenticated attacker can reach the vulnerable component over the network, making this a critical pre-auth flaw in a widely deployed unified communications product.
Description
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS score make this an urgent pre-auth SQL injection.
What it is
NuPoint Messenger in Mitel MiCollab through 9.8.0.33 fails to sanitize user input, allowing SQL injection. An unauthenticated attacker can reach the vulnerable component over the network, making this a critical pre-auth flaw in a widely deployed unified communications product.
Impact
An attacker can read sensitive information from the database and execute arbitrary database and management operations, potentially leading to full compromise of the affected system.
Attack surface
Reachable over the network via the NuPoint Messenger interface with no authentication or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.657 (99.2nd percentile), indicating a high likelihood of exploitation activity.
What to do
- Upgrade Mitel MiCollab to a version later than 9.8.0.33 per vendor advisory 24-0014.
- Restrict network access to NuPoint Messenger and MiCollab management interfaces to trusted networks only.
- Apply input validation and parameterized queries if any custom integration touches NPM.
- Monitor vendor advisory for updated fixed versions and interim mitigations.
Detection
- Inspect web and application logs for SQL metacharacters or anomalous query patterns against NuPoint Messenger endpoints.
- Alert on unexpected database errors or unusual database account activity originating from the MiCollab host.
- Baseline and monitor outbound connections from MiCollab servers for signs of data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-24-0014 | Vendor Advisory |
Track CVE-2024-35286 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-35286), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.