PT-2024-7482 · Mitel · Mitel Micollab+1

Published

2024-07-24

·

Updated

2024-10-23

·

CVE-2024-35287

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mitel MiCollab versions through 9.8 SP1 (9.8.1.5)
Description: A vulnerability in the NuPoint Messenger component could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. This issue is related to insufficient access control. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.
Recommendations: For versions through 9.8 SP1 (9.8.1.5), update to a version that addresses the privilege escalation issue in the NuPoint Messenger component. As a temporary workaround, consider restricting access to the NuPoint Messenger component to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2024-08862
CVE-2024-35287

Affected Products

Mitel Micollab
Nupoint Messenger