Mitel MiCollab Path Traversal Vulnerability
n/a — n/a
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
9.1
98.1%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Published
- Oct 21, 2024
- Modified
- Aug 4, 2026
- Added to KEV
- Jan 7, 2025
- Federal patch due
- Jan 28, 2025
CISA required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
5 foundWeaponization
Public repositories whose name or description references CVE-2024-41713, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713★ 20
updated Jul 11, 2026
- Sanandd/cve-2024-CVE-2024-41713★ 0
cve-2024-CVE-2024-41713
updated Dec 21, 2024
- zxj-hub/CVE-2024-41713POC★ 0
Mitel MiCollab 企业协作平台 任意文件读取漏洞(CVE-2024-41713)由于Mitel MiCollab软件的 NuPoint 统一消息 (NPM) 组件中存在身份验证绕过漏洞,并且输入验证不足,未经身份验证的远程攻击者可利用该漏洞执行路径遍历攻击,成功利用可能导致未授权访问、破坏或删除用户的数据和系统配置。影响范围:version < MiCollab 9.8 SP2 (9.8.2.12)
updated Dec 21, 2024
- amanverma-wsu/CVE-2024-41713-Scan★ 0
A Python script to detect CVE-2024-41713, a directory traversal vulnerability in Apache HTTP Server, enabling unauthorized access to restricted resources. This tool is for educational purposes and authorized testing only. Unauthorized usage is unethical and illegal.
updated Jan 11, 2025
- gunyakit/CVE-2024-41713-PoC-exploit★ 0
Mitel MiCollab Authentication Bypass to Arbitrary File Read
updated May 18, 2025
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2024-41713?
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
How severe is CVE-2024-41713?
CVE-2024-41713 has a CVSS base score of 9.1 out of 10 (CVSS 3.1).
Is CVE-2024-41713 actively exploited in the wild?
Yes. CVE-2024-41713 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Jan 7, 2025, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2024-41713?
98.1% - meaning FIRST.org's EPSS model estimates a 98.1% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2024-41713?
Yes - a public Nuclei template referencing CVE-2024-41713 exist in public repositories we checked. We also found 5 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2024-41713?
CVE-2024-41713 is classified under CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
Cross-checked against
Impactr finds and proves whether CVE-2024-41713 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist