CVE-2024-55550
CISA 기관 조치 기한: 2025-01-28
Mitel MiCollab
Qualys 위협 인텔 · 심각도 4/5 · QID 731976 · CGI
공개 익스플로잇
실제 공격 관측
쉬운 악용
대량 데이터 유출
악성코드 연계
랜섬웨어 연계
CISA KEV
Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.
KEV 필수 조치: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
벡터: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N