PT-2024-7493 · Mitel · Mitel Micollab+1

Published

2024-07-24

·

Updated

2025-06-24

·

CVE-2024-41714

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mitel MiCollab versions through 9.8 SP1 (9.8.1.5) MiVoice Business Solution Virtual Instance (MiVB SVI) versions through 1.0.0.27
Description: A vulnerability in the Web Interface component could allow an authenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. This could enable an attacker to execute arbitrary commands with elevated privileges within the context of the system.
Recommendations: For Mitel MiCollab versions through 9.8 SP1 (9.8.1.5), update to a version later than 9.8.1.5 to resolve the issue. For MiVoice Business Solution Virtual Instance (MiVB SVI) versions through 1.0.0.27, update to a version later than 1.0.0.27 to resolve the issue. As a temporary workaround, consider restricting access to the Web Interface component to minimize the risk of exploitation.

Fix

Code Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-08875
CVE-2024-41714

Affected Products

Mivoice Business Solution Virtual Instance
Mitel Micollab