CVE-2024-41713
KEV
🔴 Łataj teraz
Luka w NuPoint Unified Messaging umożliwia atak path traversal i nieautoryzowany dostęp do danych.
CVSS
9.1
EPSS
98.1%
Exploit
weaponized
Vendor
mitel
Opis źródłowy (NVD)
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
path-traversal
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 98.1% |
| Opublikowano (NVD) | 2024-10-21 21:15:06 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:30 UTC |
Referencje
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029 (cve@mitre.org) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-41713 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]