KEVIntel
2.7
CVSS
Low

CVE-2024-55550

PUBLISHED

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
Mitel
Product
MiCollab
Published
Dec 10, 2024
EPSS

Description

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

cisa malware nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 2.7 Low

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2025-01-07 00:00:00 UTC · Source

Used in malware

Recorded 2026-06-02 14:08:22 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 07, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus

  • Detected by Nuclei

  • Exploit Used in Malware