First published: Mon Oct 21 2024(Updated: )
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mitel NuPoint Messenger | <9.8.0.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35285 is rated as a high-severity vulnerability due to the potential for unauthorized command execution.
To mitigate CVE-2024-35285, upgrade Mitel NuPoint Messenger to a version later than 9.8.0.33.
CVE-2024-35285 allows an unauthenticated attacker to conduct command injection attacks.
Mitel NuPoint Messenger versions up to and including 9.8.0.33 are affected by CVE-2024-35285.
No, CVE-2024-35285 can be exploited by unauthenticated attackers.