← Vulnerability feed

Vulnerability record · CVE-2024-55550 · published 10 December 2024

CVE-2024-55550: Mitel MiCollab path traversal allows admin local file read

Mitel · Micollab

Mitel MiCollab through 9.8 SP2 has a path traversal flaw (CWE-22) caused by insufficient input sanitization. An authenticated attacker with administrative privileges can read local files, though the disclosure is limited to non-sensitive system information and does not allow file modification or privilege escalation.

2.7 CVSS 3.1 Low CISA KEV since 7 Jan 2025 Known ransomware use EPSS 38% · top 1.5% CWE-22 · Path traversal
2.7CVSS 3.1 base score
38%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
4 Aug 2026Last modified by NVD

Description

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityDespite a low CVSS score, it is in CISA KEV with known ransomware use and high EPSS, indicating real-world exploitation.

What it is

Mitel MiCollab through 9.8 SP2 has a path traversal flaw (CWE-22) caused by insufficient input sanitization. An authenticated attacker with administrative privileges can read local files, though the disclosure is limited to non-sensitive system information and does not allow file modification or privilege escalation.

Impact

The attacker gains read access to resources constrained to the admin access level, limited to non-sensitive system information. No file modification or privilege escalation is possible.

Attack surface

Reachable over the network (AV:N) with no user interaction (UI:N), but requires high privileges (PR:H), meaning a valid administrative account is needed.

Exploitation

CISA added it to KEV on 2025-01-07 with known ransomware campaign use, and EPSS is 0.379 (98.5th percentile), indicating active exploitation in the wild.

What to do

  • Apply the vendor mitigation or update per Mitel security advisory MISA-2024-0029.
  • If no fix is available, discontinue use of the product as directed by CISA.
  • Restrict administrative access to MiCollab to trusted networks and accounts.
  • Audit and rotate credentials for administrative accounts that may be exposed.

Detection

  • Monitor MiCollab logs for path traversal patterns in requests from administrative sessions.
  • Alert on unexpected local file read activity by admin users.
  • Review administrative account activity for anomalous file access sequences.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-55550 to the Known Exploited Vulnerabilities catalog on 7 January 2025 as "Mitel MiCollab Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 January 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-55550 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26143Mitel MiCollab TP-240 missing authentication enables DDoS and data exposureThe TP-240 (tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 lacks authentication for a critical fun…KEVEPSS 87%analysed9.1CVE-2024-41713Mitel MiCollab NuPoint path traversal allows unauthenticated file accessMitel MiCollab's NuPoint Unified Messaging component fails to validate input, allowing a path traversal attack through version 9.8 SP1 FP2 (9.8.1.201…KEVEPSS 98%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed9.8CVE-2024-35285Mitel micollab command injection vulnerabilityA vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attac…EPSS 1.3%9.8CVE-2024-35286Mitel MiCollab NuPoint Messenger unauthenticated SQL injectionNuPoint Messenger in Mitel MiCollab through 9.8.0.33 fails to sanitize user input, allowing SQL injection. An unauthenticated attacker can reach the …EPSS 66%analysed9.8CVE-2024-35314Mitel micollab code injection vulnerabilityA vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could …EPSS 1.8%9.8CVE-2022-41326Mitel micollab missing authorization vulnerabilityThe web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper…EPSS 1.5%9.8CVE-2022-36452Mitel micollab unrestricted file upload vulnerabilityA vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious fil…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2024-55550), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.