CVE-2024-41713
Mitel MiCollab Path Traversal Vulnerability
- Published
- Oct 21, 2024
- Updated
- Aug 4, 2026
- Assigning CNA
- mitre
- Evidence observed
- Jan 7, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
Sources
4- CVE-2024-41713-ScanScanner
Python script to detect CVE-2024-41713 directory traversal in Apache HTTP Server, providing response snippets for verification. For educational and authorized testing only.
Proof-of-concept exploit for CVE-2024-41713, demonstrating authentication bypass in Mitel MiCollab leading to arbitrary file read. Includes a Python script for testing affected versions.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.