PatchSiren cyber security CVE debrief
CVE-2024-41713 Mitel CVE debrief
CVE-2024-41713 is a path traversal vulnerability in Mitel MiCollab that CISA added to the Known Exploited Vulnerabilities catalog on 2025-01-07. The KEV entry marks the issue as known exploited and notes known ransomware campaign use, so organizations should treat it as an active defensive priority and follow vendor guidance or discontinue use if mitigation is unavailable.
- Vendor
- Mitel
- Product
- MiCollab
- CVSS
- CRITICAL 9.1
- CISA KEV
- Listed
- Original CVE published
- 2025-01-07
- Original CVE updated
- 2025-01-07
- Advisory published
- 2025-01-07
- Advisory updated
- 2025-01-07
Who should care
Teams responsible for Mitel MiCollab deployments, security operations, vulnerability management, and incident response.
Technical summary
The supplied official sources identify CVE-2024-41713 as a path traversal vulnerability affecting Mitel MiCollab. The corpus does not include affected versions, exploitation mechanics, or remediation details beyond CISA's reference to a Mitel security advisory. CISA lists the vulnerability as known exploited and indicates known ransomware campaign use.
Defensive priority
High. CISA KEV inclusion indicates active exploitation risk, and the supplied timeline gives a mitigation due date of 2025-01-28.
Recommended defensive actions
- Review the Mitel security advisory referenced by CISA for vendor-supported mitigation steps.
- Apply mitigations per vendor instructions, or discontinue use of the product if mitigations are unavailable.
- Inventory all MiCollab instances and confirm whether they are exposed or in scope.
- Prioritize remediation before the KEV due date of 2025-01-28.
- Review relevant logs and access activity for signs of unauthorized file or path access around affected systems.
Evidence notes
This debrief is limited to the supplied corpus and official links. CISA's KEV metadata identifies the vulnerability as Mitel MiCollab path traversal, dateAdded 2025-01-07, dueDate 2025-01-28, and knownRansomwareCampaignUse as Known. The source metadata also references Mitel security advisory MISA-2024-0029 and the NVD record, but the advisory text and NVD details are not included in the provided corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-41713 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-41713
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-41713 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-41713
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.