A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://www.securityweek.com/aquabot-botnet-targeting-vulnerable-mitel-phones/
https://www.securityweek.com/cisa-warns-of-mitel-micollab-vulnerabilities-exploited-in-attacks/
https://thehackernews.com/2025/01/cisa-flags-critical-flaws-in-mitel-and.html
https://github.com/exploitintel/eip-search
https://github.com/gunyakit/CVE-2024-41713-PoC-exploit
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/amanverma-wsu/CVE-2024-41713-Scan
https://github.com/Sanandd/cve-2024-CVE-2024-41713
https://github.com/zxj-hub/CVE-2024-41713POC
https://github.com/watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713
https://github.com/iSee857/CVE-PoC
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-41713