CVE-2024-55550

CVE Published 2024-12-10
Related CWE(s) CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Related Vendor(s) mitel
Related Product(s) micollab
Exploitation Reported (CISA KEV) 2025-01-07
CVSS 3 Base Score 4.4 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References