RULE(RULE ID:338604)

Rule General Information
Release Date: 2024-12-17
Rule Name: Mitel MiCollab Arbitrary File Read Vulnerability (CVE-2024-41713)
Severity:
CVE ID:
Rule Protection Details
Description: A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029
Solutions
Please refer to announcements or patches release by the vendor: https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029