Skip to content
COOEY

FAIL › dossier

MiCollab

PRODUCT

· dossier confidence 0%

MiCollab is a business collaboration platform from Mitel that suffered critical path traversal vulnerabilities allowing unauthenticated remote code execution and privilege escalation. The security posture is severely degraded by multiple unpatched flaws that can be chained for full server compromise.

PROFILE
Categorycollaboration softwareWhat they doMiCollab is a collaboration and communication platform developed by Mitel for business use.
SECURITY POSTURE

The security posture is critically compromised by multiple unpatched path traversal vulnerabilities that allow both unauthenticated remote code execution and authenticated privilege escalation, indicating severe gaps in input validation and access control mechanisms.

Notable failures
  • CVE-2024-41713 unauthenticated RCE via path traversal
  • CVE-2024-55550 authenticated file read and privilege escalation
  • CVE-2024-41713 NuPoint Unified Messaging component flaw
Patterns: repeated unpatched path traversal RCEs; chained vulnerabilities enabling full server compromise
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2025-01-07 CVE-2024-41713 critical Mitel MiCollab's path traversal flaw allows unauthenticated attackers to bypass security controls and chain with CVE-2024-55550 for full server compromise.
2025-01-07 CVE-2024-55550 critical Mitel MiCollab's path traversal flaw lets authenticated admins read local files, which can be chained with an unauthenticated remote file-read bug to escalate privileges or exfiltrate data.
2024-10-21 CVE-2024-41713 critical CVE-2024-41713: A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiColl
Open questions: Mitel founding date and headquarters location · MiCollab product launch date and current version status
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-26 04:30:16.952402+00:00