← לוח פגיעויות

CVE-2024-55550

נמוכה 2.7 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Mitel MiCollab Path Traversal Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

מדדים

CVSS 3.1
2.7 (LOW) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
EPSS — סבירות ניצול
38% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-22

מוצרים מושפעים

mitel: micollab

קישורים