PoC Index

CVE-2024-55550

KEV RANSOMWAREMEDIUM 4.4EPSS 37.8%

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVSS v3.1
2.7 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
37.85% chance of exploitation in the next 30 days, 98th percentile
CISA KEV
added 2025-01-07, used in ransomware campaigns
Nuclei
critical · CWE-22
Published
2024-12-10
Updated
2026-08-04

Nuclei templates (1)

References

Related