Skip to content
COOEY

FAIL › dossier

Mitel

VENDOR

· dossier confidence 60%

Mitel, a provider of unified communications and collaboration solutions, has a concerning history of critical security vulnerabilities, including remote code execution flaws frequently exploited by ransomware. Their products require careful assessment and mitigation strategies within a DIB/CMMC environment.

PROFILE
CategoryUnified Communications & CollaborationWhat they doMitel designs, develops, manufactures, markets, sells, and supports comprehensive communication and collaboration solutions. They offer unified communications, cloud-based contact center solutions, and critical communications systems.Size1,000-5,000 employeesOwnershipprivate Websitehttps://www.mitel.com/ ↗
SECURITY POSTURE

Mitel has demonstrated a history of critical vulnerabilities in its products, particularly MiCollab and MiVoice Connect, frequently exploited in the wild and linked to ransomware. The repeated occurrence of remote code execution vulnerabilities suggests potential weaknesses in their development and security testing processes.

Notable failures
  • CVE-2022-41223: Critical RCE exploited by ransomware
  • CVE-2022-29499: Critical RCE exploited by ransomware
  • CVE-2024-41713: Critical path traversal RCE
  • CVE-2022-40765: Critical RCE via command injection
  • CVE-2024-41710: High-severity RCE in SIP phones
  • CVE-2022-26143: Unauthorized access and data exfiltration
Patterns: Repeated critical remote code execution (RCE) vulnerabilities; Vulnerabilities actively exploited in the wild and linked to ransomware; Path traversal flaws; Command injection vulnerabilities
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2025-01-07 CVE-2024-41713 critical Mitel MiCollab's path traversal flaw allows unauthenticated attackers to bypass security controls and chain with CVE-2024-55550 for full server compromise.
2023-02-21 CVE-2022-41223 critical An authenticated internal attacker could execute code in Mitel MiVoice Connect via CVE-2022-41223, a vulnerability actively exploited in the wild and linked to ransomware.
2022-06-27 CVE-2022-29499 critical Mitel MiVoice Connect suffered a critical remote code execution flaw due to incorrect data validation that was actively exploited in the wild and linked to ransomware.
2025-01-07 CVE-2024-55550 critical Mitel MiCollab's path traversal flaw lets authenticated admins read local files, which can be chained with an unauthenticated remote file-read bug to escalate privileges or exfiltrate data.
2023-02-21 CVE-2022-40765 critical An authenticated attacker with internal network access can execute arbitrary commands on Mitel MiVoice Connect via a command injection flaw in the Edge Gateway component.
2025-02-12 CVE-2024-41710 high Mitel SIP phones have a boot-time argument injection vulnerability actively exploited in the wild, allowing arbitrary command execution.
2022-03-25 CVE-2022-26143 high Mitel's MiCollab and MiVoice Business Express suffered an access control vulnerability allowing unauthorized access, DoS, and data exposure.
2024-10-21 CVE-2024-41713 critical CVE-2024-41713: A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiColl
2022-04-26 CVE-2022-29499 critical CVE-2022-29499: The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows
Open questions: What is Mitel's current headquarters location? · What is Mitel's current size (employee count or revenue)? · What is Mitel's ownership structure? · What is Mitel's website URL?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:51:34.012651+00:00