PT-2024-7482 · Mitel · Mitel Micollab+1
Published
2024-07-24
·
Updated
2024-10-23
·
CVE-2024-35287
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mitel MiCollab versions through 9.8 SP1 (9.8.1.5)
Description:
A vulnerability in the NuPoint Messenger component could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. This issue is related to insufficient access control. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges.
Recommendations:
For versions through 9.8 SP1 (9.8.1.5), update to a version that addresses the privilege escalation issue in the NuPoint Messenger component. As a temporary workaround, consider restricting access to the NuPoint Messenger component to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mitel Micollab
Nupoint Messenger