Mitel
Mitel Micollab: vulnerabilidades y CVE
Mitel Micollab tiene 49 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 12 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE49
Últimos 12 meses0
Críticas12
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-41713 | Crítica (9.1) | 98% | ⚠ Explotación activa | 21 oct 2024 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input… |
| CVE-2024-55550 | Baja (2.7) | 38% | ⚠ Explotación activa | 10 dic 2024 | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated… |
| CVE-2014-0160 | Alta (7.5) | 100% | ⚠ Explotación activa | 7 abr 2014 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted… |
| CVE-2022-26143 | Crítica (9.8) | 87% | ⚠ Explotación activa | 10 mar 2022 | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-52914 | Alta (8.8) | 0.64% | — | 8 ago 2025 | A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an authenticated attacker to conduct a SQL Injection attack due to insufficient validation of… |
| CVE-2025-52913 | Crítica (9.8) | 0.52% | — | 8 ago 2025 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker to conduct a path traversal attack due to insufficient input… |
| CVE-2024-55550 | Baja (2.7) | 38% | ⚠ Explotación activa | 10 dic 2024 | Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated… |
| CVE-2024-47224 | Media (6.5) | 0.36% | — | 21 oct 2024 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate… |
| CVE-2024-41714 | Alta (8.8) | 1.3% | — | 21 oct 2024 | A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a… |
| CVE-2024-41713 | Crítica (9.1) | 98% | ⚠ Explotación activa | 21 oct 2024 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input… |
| CVE-2024-41712 | Media (6.6) | 0.55% | — | 21 oct 2024 | A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful… |
| CVE-2024-35315 | Media (5.6) | 0.77% | — | 21 oct 2024 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation… |
| CVE-2024-35314 | Crítica (9.8) | 1.8% | — | 21 oct 2024 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection… |
| CVE-2024-35287 | Media (6.7) | 0.21% | — | 21 oct 2024 | A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack… |
| CVE-2024-35286 | Crítica (9.8) | 66% | — | 21 oct 2024 | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit… |
| CVE-2024-35285 | Crítica (9.8) | 1.3% | — | 21 oct 2024 | A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. |
| CVE-2024-30160 | Media (4.8) | 0.32% | — | 21 oct 2024 | A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack… |
| CVE-2024-30159 | Media (4.8) | 0.32% | — | 21 oct 2024 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to… |
| CVE-2024-30158 | Alta (7.2) | 0.41% | — | 21 oct 2024 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation… |
| CVE-2024-30157 | Alta (7.2) | 0.41% | — | 21 oct 2024 | A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient… |
| CVE-2024-47912 | Alta (8.2) | 0.38% | — | 21 oct 2024 | A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to… |
| CVE-2024-47223 | Crítica (9.4) | 0.48% | — | 21 oct 2024 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient… |
| CVE-2024-47189 | Alta (7.7) | 0.42% | — | 21 oct 2024 | The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct SQL injection due to insufficient… |
| CVE-2023-25597 | Media (5.9) | 0.68% | — | 14 abr 2023 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.6.2.9 could allow an unauthenticated attacker to download a shared file via a crafted request - including the exact path and filename - due… |
| CVE-2022-41326 | Crítica (9.8) | 1.5% | — | 22 nov 2022 | The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code… |
| CVE-2022-36452 | Crítica (9.8) | 0.91% | — | 25 oct 2022 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary… |
| CVE-2022-36454 | Media (6.5) | 0.53% | — | 25 oct 2022 | A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit could… |
| CVE-2022-36453 | Alta (8.8) | 0.63% | — | 25 oct 2022 | A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorization controls. A successful exploit… |
| CVE-2022-36451 | Alta (8.8) | 0.63% | — | 25 oct 2022 | A vulnerability in the MiCollab Client server component of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to conduct a Server-Side Request Forgery (SSRF) attack due to insufficient restriction of… |
| CVE-2022-26143 | Crítica (9.8) | 87% | ⚠ Explotación activa | 10 mar 2022 | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance… |
| CVE-2021-32072 | Media (6.5) | 0.80% | — | 13 ago 2021 | The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code information (disclosing sensitive application data) due to insufficient output sanitization. A successful… |
| CVE-2021-32071 | Crítica (9.8) | 1.2% | — | 13 ago 2021 | The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control. A successful exploit could allow an attacker to view and modify… |
| CVE-2021-32070 | Media (5.4) | 0.64% | — | 13 ago 2021 | The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the… |
| CVE-2021-32069 | Media (4.8) | 0.52% | — | 13 ago 2021 | The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to improper TLS negotiation. A successful exploit could allow an attacker to view and modify data. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.