CVE-2024-55550: Mitel MiCollab Path Traversal Vulnerability
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
Other sources
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55550?
CVE-2024-55550 has been classified as a high severity vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2024-55550?
To fix CVE-2024-55550, ensure that all affected versions of Mitel MiCollab are updated to the latest release that contains the necessary security patches.
Who is affected by CVE-2024-55550?
CVE-2024-55550 affects users of Mitel MiCollab versions prior to 9.8 and 9.8-sp1 that have administrative privileges.
What is the nature of the vulnerability in CVE-2024-55550?
CVE-2024-55550 is a path traversal vulnerability that arises from insufficient input sanitization in Mitel MiCollab.
Can CVE-2024-55550 be exploited remotely?
The exploitation of CVE-2024-55550 requires authenticated access with administrative privileges, making it a controlled risk.