PT-2024-7493 · Mitel · Mitel Micollab+1

CVE-2024-41714

·

Published

2024-07-24

·

Updated

2025-06-24

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mitel MiCollab versions through 9.8 SP1 (9.8.1.5) MiVoice Business Solution Virtual Instance (MiVB SVI) versions through 1.0.0.27
Description: A vulnerability in the Web Interface component could allow an authenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. This could enable an attacker to execute arbitrary commands with elevated privileges within the context of the system.
Recommendations: For Mitel MiCollab versions through 9.8 SP1 (9.8.1.5), update to a version later than 9.8.1.5 to resolve the issue. For MiVoice Business Solution Virtual Instance (MiVB SVI) versions through 1.0.0.27, update to a version later than 1.0.0.27 to resolve the issue. As a temporary workaround, consider restricting access to the Web Interface component to minimize the risk of exploitation.

Fix

Code Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08875
CVE-2024-41714

Affected Products

Mivoice Business Solution Virtual Instance
Mitel Micollab