S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 10, 2024

CVE-2024-41713 Scanner

CVE-2024-41713 Scanner - Path Traversal vulnerability in Mitel MiCollab

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-41713
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
micollabby mitel
0
Updated Sep 10, 2026View on NVD →
Detail

The Mitel MiCollab software is a unified communication solution widely used in enterprises for voice, messaging, and collaboration services. It integrates with various communication platforms, allowing organizations to enhance productivity and streamline operations. This software is deployed on premises or in the cloud, providing flexible deployment options. Due to its extensive feature set, it is often used in environments where secure communication and collaboration are paramount. Mitel MiCollab is particularly popular in industries requiring reliable and scalable communication tools. As a critical component in enterprise communication infrastructures, its security is essential to maintaining operational integrity.

Path traversal vulnerabilities enable attackers to manipulate file paths, bypassing input validation to access unauthorized resources on a server. This vulnerability in Mitel MiCollab arises from improper handling of user input in the NuPoint Unified Messaging (NPM) component. It can be exploited by unauthenticated attackers, providing unauthorized access to files and system configurations. If left unaddressed, it could expose sensitive data or disrupt system functionality. By exploiting this vulnerability, attackers may also target configuration files critical to the system's operation. Mitel MiCollab users should urgently evaluate their deployments to mitigate risks associated with this vulnerability.

Technically, the vulnerability exploits insufficient input validation in the NuPoint Unified Messaging component. Attackers send crafted HTTP requests containing traversal sequences to access restricted directories. The endpoint "/npm-pwg/..;/axis2-AWC/services/listServices" is particularly vulnerable. Upon successful exploitation, the server responds with accessible service information, indicating the attack's success. This lack of input sanitization can allow attackers to enumerate sensitive files. Exploiting this vulnerability requires no prior authentication, increasing its severity. The combination of an easily exploitable endpoint and high impact underscores the critical nature of this vulnerability.

If exploited, attackers could gain unauthorized access to sensitive files, including user data and system configurations. This could compromise the confidentiality and integrity of organizational data. Additionally, attackers might modify or delete essential files, potentially disrupting services provided by Mitel MiCollab. Exploitation could also allow attackers to map internal systems, increasing the likelihood of subsequent attacks. Such disruptions may lead to operational downtime and reputational damage. Organizations must act quickly to mitigate the risks posed by this vulnerability.

REFERENCES

Solution Advice
  • Apply patches or updates provided by Mitel to address this vulnerability.
  • Enable robust input validation on all endpoints handling user input.
  • Restrict unauthorized access to critical endpoints using proper access controls.
  • Monitor system logs for unusual activity related to sensitive file access.
  • Implement web application firewalls to block malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-41713 Scanner - Path Traversal vulnerability in Mitel MiCollab | S4E