{"id":"CVE-2024-55550","title":"Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization","summary":"Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to…","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-22","CWE-22"],"vendor":"mitel","product":"micollab","affected":["micollab <= 9.8.1.201"],"published":"2024-12-10","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-55550","references":[{"url":"https://www.mitel.com/support/security-advisories","label":"cve@mitre.org"},{"url":"https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029","label":"cve@mitre.org"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55550","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.37899,"epssPercentile":0.98526,"kev":true,"kevDateAdded":"2025-01-07","kevDueDate":"2025-01-28","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-04T05:36:12.697Z","exploits":{"nuclei":["CVE-2024-55550"],"checkedAt":"2026-09-21T15:26:47.950Z"},"exploitAvailable":true,"slug":"CVE-2024-55550","body":"## Overview\n\nMitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.\n\n## Affected\n\n- `micollab <= 9.8.1.201`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":52,"depthScoreParts":{"impact":14.9,"likelihood":7.6,"exploitation":25,"ransomware":5},"changes":[{"seq":4740,"id":"CVE-2024-55550","ts":1788887203290,"field":"exploit_available","old":"false","new":"true"},{"seq":3623,"id":"CVE-2024-55550","ts":1788886319461,"field":"exploit_available","old":"true","new":"false"},{"seq":2477,"id":"CVE-2024-55550","ts":1788882988006,"field":"exploit_available","old":"false","new":"true"},{"seq":1506,"id":"CVE-2024-55550","ts":1788882401572,"field":"exploit_available","old":"true","new":"false"},{"seq":620,"id":"CVE-2024-55550","ts":1788881838239,"field":"exploit_available","old":"false","new":"true"}]}