Vulnerability record · CVE-2024-41713 · published 21 October 2024
CVE-2024-41713: Mitel MiCollab NuPoint path traversal allows unauthenticated file access
Mitel · Micollab
Mitel MiCollab's NuPoint Unified Messaging component fails to validate input, allowing a path traversal attack through version 9.8 SP1 FP2 (9.8.1.201). An unauthenticated attacker can reach user data and system configuration files, which makes this a serious exposure for internet-facing deployments.
Description
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityUnauthenticated network path traversal with high confidentiality and integrity impact, active KEV listing, ransomware association, and near-certain EPSS score.
What it is
Mitel MiCollab's NuPoint Unified Messaging component fails to validate input, allowing a path traversal attack through version 9.8 SP1 FP2 (9.8.1.201). An unauthenticated attacker can reach user data and system configuration files, which makes this a serious exposure for internet-facing deployments.
Impact
An attacker can view, corrupt, or delete users' data and system configurations without authentication. Integrity and confidentiality are both rated high, so tampering and data theft are both realistic outcomes.
Attack surface
Reachable over the network via the NuPoint Unified Messaging component with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any exposed MiCollab instance running the affected build is a candidate target.
Exploitation
Listed in CISA KEV since 2025-01-07 with a 2025-01-28 remediation due date and flagged for known ransomware campaign use. EPSS is 0.9811 (99.91st percentile), indicating active, widespread exploitation.
What to do
- Apply the vendor fix from Mitel security advisory MISA-2024-0029 for MiCollab, upgrading past 9.8 SP1 FP2 (9.8.1.201).
- If patching is not immediately possible, follow CISA KEV guidance: apply vendor mitigations or discontinue use of the product.
- Remove MiCollab and its NuPoint component from direct internet exposure; restrict access to trusted networks or VPN.
- Rotate credentials and review stored configuration data on any instance that may have been exposed.
- Monitor Mitel advisories for updated builds and re-check affected versions before redeploying.
Detection
- Review web and application logs for path traversal patterns (../, encoded variants) against NuPoint endpoints.
- Alert on unexpected reads, writes, or deletions of NuPoint user data and configuration files.
- Hunt for anomalous outbound connections or file access from the MiCollab host consistent with post-exploitation.
- Correlate host and network telemetry with CISA KEV timelines for signs of ransomware staging.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-41713 to the Known Exploited Vulnerabilities catalog on 7 January 2025 as "Mitel MiCollab Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 January 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-41713 | US Government Resource |
Track CVE-2024-41713 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-41713), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.