← Vulnerability feed

Vulnerability record · CVE-2024-41713 · published 21 October 2024

CVE-2024-41713: Mitel MiCollab NuPoint path traversal allows unauthenticated file access

Mitel · Micollab

Mitel MiCollab's NuPoint Unified Messaging component fails to validate input, allowing a path traversal attack through version 9.8 SP1 FP2 (9.8.1.201). An unauthenticated attacker can reach user data and system configuration files, which makes this a serious exposure for internet-facing deployments.

9.1 CVSS 3.1 Critical CISA KEV since 7 Jan 2025 Known ransomware use EPSS 98% · top 0.1% CWE-22 · Path traversal
9.1CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
4 Aug 2026Last modified by NVD

Description

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network path traversal with high confidentiality and integrity impact, active KEV listing, ransomware association, and near-certain EPSS score.

What it is

Mitel MiCollab's NuPoint Unified Messaging component fails to validate input, allowing a path traversal attack through version 9.8 SP1 FP2 (9.8.1.201). An unauthenticated attacker can reach user data and system configuration files, which makes this a serious exposure for internet-facing deployments.

Impact

An attacker can view, corrupt, or delete users' data and system configurations without authentication. Integrity and confidentiality are both rated high, so tampering and data theft are both realistic outcomes.

Attack surface

Reachable over the network via the NuPoint Unified Messaging component with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any exposed MiCollab instance running the affected build is a candidate target.

Exploitation

Listed in CISA KEV since 2025-01-07 with a 2025-01-28 remediation due date and flagged for known ransomware campaign use. EPSS is 0.9811 (99.91st percentile), indicating active, widespread exploitation.

What to do

  • Apply the vendor fix from Mitel security advisory MISA-2024-0029 for MiCollab, upgrading past 9.8 SP1 FP2 (9.8.1.201).
  • If patching is not immediately possible, follow CISA KEV guidance: apply vendor mitigations or discontinue use of the product.
  • Remove MiCollab and its NuPoint component from direct internet exposure; restrict access to trusted networks or VPN.
  • Rotate credentials and review stored configuration data on any instance that may have been exposed.
  • Monitor Mitel advisories for updated builds and re-check affected versions before redeploying.

Detection

  • Review web and application logs for path traversal patterns (../, encoded variants) against NuPoint endpoints.
  • Alert on unexpected reads, writes, or deletions of NuPoint user data and configuration files.
  • Hunt for anomalous outbound connections or file access from the MiCollab host consistent with post-exploitation.
  • Correlate host and network telemetry with CISA KEV timelines for signs of ransomware staging.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-41713 to the Known Exploited Vulnerabilities catalog on 7 January 2025 as "Mitel MiCollab Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 January 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-41713 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26143Mitel MiCollab TP-240 missing authentication enables DDoS and data exposureThe TP-240 (tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 lacks authentication for a critical fun…KEVEPSS 87%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed2.7CVE-2024-55550Mitel MiCollab path traversal allows admin local file readMitel MiCollab through 9.8 SP2 has a path traversal flaw (CWE-22) caused by insufficient input sanitization. An authenticated attacker with administr…KEVEPSS 38%analysed9.8CVE-2024-35285Mitel micollab command injection vulnerabilityA vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attac…EPSS 1.3%9.8CVE-2024-35286Mitel MiCollab NuPoint Messenger unauthenticated SQL injectionNuPoint Messenger in Mitel MiCollab through 9.8.0.33 fails to sanitize user input, allowing SQL injection. An unauthenticated attacker can reach the …EPSS 66%analysed9.8CVE-2024-35314Mitel micollab code injection vulnerabilityA vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could …EPSS 1.8%9.8CVE-2022-41326Mitel micollab missing authorization vulnerabilityThe web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper…EPSS 1.5%9.8CVE-2022-36452Mitel micollab unrestricted file upload vulnerabilityA vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious fil…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2024-41713), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.