Skip to main content

Mitel security briefs

5 published alerts for Mitel products and services.

Actively exploited (KEV)Ransomware

CVE-2024-55550

Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-55550). Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server. CISA remediation due date: 2025-01-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-41713

Mitel MiCollab Path Traversal Vulnerability

Mitel MiCollab is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-41713). Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server. CISA remediation due date: 2025-01-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-41223

Mitel MiVoice Connect Code Injection Vulnerability

Mitel MiVoice Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-41223). The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application. CISA remediation due date: 2023-03-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-40765

Mitel MiVoice Connect Command Injection Vulnerability

Mitel MiVoice Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-40765). The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system. CISA remediation due date: 2023-03-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-29499

Mitel MiVoice Connect Data Validation Vulnerability

Mitel MiVoice Connect is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-29499). The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. CISA remediation due date: 2022-07-18. If you need help checking exposure, call (864) 335-9223.