CVE-2024-41713
Last modified
CVE-2024-41713 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.. CISA has confirmed active exploitation in the wild. EPSS estimates a 98.11% chance of exploitation in the next 30 days.
Description
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mitel | Micollab | <= 9.8.1.201 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-41713?
How severe is CVE-2024-41713?
How do I fix CVE-2024-41713?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41708An issue was discovered in AdaCore ada_web_services 20.0 all…7.5
- CVE-2024-41709Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not…4.8
- CVE-2024-4171A vulnerability classified as critical has been found in Ten…8.8
- CVE-2024-41710A vulnerability in the Mitel 6800 Series, 6900 Series, and 6…7.2
- CVE-2024-41711A vulnerability in the Mitel 6800 Series, 6900 Series, and 6…6.8
- CVE-2024-41712A vulnerability in the Web Conferencing Component of Mitel M…6.6
- CVE-2024-41714A vulnerability in the Web Interface component of Mitel MiCo…8.8
- CVE-2024-41715The goTenna Pro ATAK Plugin does not inject extra characters…4.3
- CVE-2024-41716Cleartext storage of sensitive information vulnerability exi…8.1
- CVE-2024-41717Kieback & Peter's DDC4000 series is vulnerable to a path tra…9.8
- CVE-2024-41718Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID. Consul…
- CVE-2024-41719When generating QKView of BIG-IP Next instance from the BIG-…5.5
Are you affected by CVE-2024-41713?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
