S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 11, 2025

CVE-2024-55550 Scanner

CVE-2024-55550 Scanner - Arbitrary File Read vulnerability in Mitel MiCollab

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-55550
4.4
CVSSmedium
Requires local system access · requires high privileges.

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

Attack Vector
Local
Privileges Req.
High
User Interaction
None
Affected
n/aby n/a
n/a
Updated Sep 10, 2026View on NVD →
Detail

Mitel MiCollab is a business communication platform used by enterprises for collaboration, messaging, and conferencing. It provides employees with tools for communication, including voice, video, and messaging capabilities. The platform integrates with existing enterprise infrastructure to enhance communication workflows. Organizations utilize MiCollab for internal team collaboration and external communication with clients. It is widely deployed in businesses that require secure and efficient communication solutions. The software is accessible via desktop and mobile applications.

The Arbitrary File Read vulnerability in Mitel MiCollab allows an unauthenticated attacker to access sensitive files on the server. This occurs due to improper input validation, enabling path traversal attacks. An attacker can exploit this vulnerability by sending specially crafted requests to the server. This flaw can lead to unauthorized access to system configurations, credentials, or other sensitive information. If exploited, attackers can use the accessed data for further attacks. This vulnerability represents a critical risk to affected systems.

The vulnerability exists in endpoints that fail to validate and sanitize file access requests properly. Attackers can exploit this by using directory traversal sequences to navigate the file system. The affected endpoint allows remote requests to specify arbitrary file paths, bypassing access controls. By crafting a malicious request, an attacker can retrieve files containing sensitive information such as system credentials. The flaw affects both GET and POST request-based interactions. As a result, unauthorized users can retrieve critical system files without authentication.

If exploited, this vulnerability can lead to significant security risks for affected organizations. Attackers can obtain credentials stored in configuration files, leading to unauthorized access to the system. Sensitive business or personal data stored on the system may be leaked. Malicious actors could use the retrieved information to escalate privileges or conduct further attacks. The exposure of system files may also facilitate remote code execution if additional vulnerabilities exist. Ultimately, this issue can compromise the confidentiality and integrity of enterprise communication systems.

REFERENCES

Solution Advice
  • Implement strict input validation to prevent directory traversal attacks.
  • Restrict file access permissions to limit exposure of sensitive files.
  • Apply patches and security updates provided by Mitel to fix the vulnerability.
  • Use web application firewalls (WAF) to block malicious requests.
  • Monitor server logs for unauthorized file access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-55550 Scanner - Arbitrary File Read vulnerability in Mitel MiCollab | S4E