{"id":"CVE-2024-41713","title":"A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation","summary":"A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-22","CWE-22"],"vendor":"mitel","product":"micollab","affected":["micollab <= 9.8.1.201"],"published":"2024-10-21","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-41713","references":[{"url":"https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029","label":"cve@mitre.org"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-41713","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.9811,"epssPercentile":0.9991,"kev":true,"kevDateAdded":"2025-01-07","kevDueDate":"2025-01-28","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-04T05:36:12.545Z","exploits":{"github":5,"githubRepos":["https://github.com/watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713","https://github.com/zxj-hub/CVE-2024-41713POC","https://github.com/Sanandd/cve-2024-CVE-2024-41713"],"nuclei":["CVE-2024-41713"],"checkedAt":"2026-09-15T16:16:03.910Z"},"exploitAvailable":true,"slug":"CVE-2024-41713","body":"## Overview\n\nA vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.\n\n## Affected\n\n- `micollab <= 9.8.1.201`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":50.1,"likelihood":19.6,"exploitation":25,"ransomware":5},"changes":[{"seq":4728,"id":"CVE-2024-41713","ts":1788887202623,"field":"exploit_available","old":"false","new":"true"},{"seq":3611,"id":"CVE-2024-41713","ts":1788886318757,"field":"exploit_available","old":"true","new":"false"},{"seq":2465,"id":"CVE-2024-41713","ts":1788882987346,"field":"exploit_available","old":"false","new":"true"},{"seq":1494,"id":"CVE-2024-41713","ts":1788882400831,"field":"exploit_available","old":"true","new":"false"},{"seq":608,"id":"CVE-2024-41713","ts":1788881837499,"field":"exploit_available","old":"false","new":"true"}]}