mitel has 3 CVEs on record between 2022 and 2024. The median CVSS is 9.1 (critical), with 2 rated critical. The median gap from publication to a KEV listing is 62 days (3 cases). Most affected products: micollab (2), mivoice_connect (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 100% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- 62 d median(3)
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2024-41713Critical· 9.1A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation100CVE-2022-29499Critical· 9.8The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation95CVE-2024-55550Low· 2.7Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization52
mitel vulnerabilities
CVEs affecting mitel, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2024-55550Low· 2.7CISA KEVPoCMitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to…
CVE-2024-41713Critical· 9.1CISA KEVPoCA vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…
CVE-2022-29499Critical· 9.8CISA KEVThe Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.