CVE-2024-35285: Command Injection
Published Oct 21, 2024
·Updated
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.
Affected Software
2 affected components
Mitel NuPoint Messenger<9.8.0.33
Mitel MiCollab<=9.8.0.33
Event History
Oct 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35285?
CVE-2024-35285 is rated as a high-severity vulnerability due to the potential for unauthorized command execution.
2
How do I fix CVE-2024-35285?
To mitigate CVE-2024-35285, upgrade Mitel NuPoint Messenger to a version later than 9.8.0.33.
3
What type of attack can be executed using CVE-2024-35285?
CVE-2024-35285 allows an unauthenticated attacker to conduct command injection attacks.
4
What versions of Mitel NuPoint Messenger are affected by CVE-2024-35285?
Mitel NuPoint Messenger versions up to and including 9.8.0.33 are affected by CVE-2024-35285.
5
Is authentication required to exploit CVE-2024-35285?
No, CVE-2024-35285 can be exploited by unauthenticated attackers.