PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-55550 Mitel CVE debrief

CVE-2024-55550 is a path traversal vulnerability affecting Mitel MiCollab. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-07 and marked known ransomware campaign use as Known, so defenders should treat it as a high-priority exposure even though the supplied corpus does not include a CVSS score or detailed exploit mechanics.

Vendor
Mitel
Product
MiCollab
CVSS
LOW 2.7
CISA KEV
Listed
Original CVE published
2025-01-07
Original CVE updated
2025-01-07
Advisory published
2025-01-07
Advisory updated
2025-01-07

Who should care

Mitel MiCollab administrators, vulnerability management teams, SOC and incident response staff, and anyone responsible for patching, mitigation, or service retirement decisions for deployed MiCollab instances.

Technical summary

The official records in the supplied corpus identify the issue as a path traversal vulnerability in Mitel MiCollab. No CVSS score, affected-version list, or deeper technical write-up is included here. The strongest defensive signal is CISA's KEV listing on 2025-01-07, which indicates known exploitation and sets a remediation due date of 2025-01-28, alongside guidance to apply vendor mitigations or discontinue use if mitigations are unavailable.

Defensive priority

Critical

Recommended defensive actions

  • Confirm whether any Mitel MiCollab instances are deployed in your environment and inventory their versions and exposure.
  • Apply Mitel's vendor mitigations or updates referenced by CISA as soon as possible; if mitigations are unavailable, follow CISA guidance to discontinue use of the product.
  • Review logs and security monitoring for suspicious activity affecting MiCollab and related authentication, file-access, or request-handling paths.
  • Escalate to incident response if there is any sign of exploitation, given KEV inclusion and the known ransomware campaign use flag.
  • Track remediation against the CISA KEV due date of 2025-01-28 and verify that mitigation is complete across all environments.

Evidence notes

Evidence is limited to the supplied official records: the CVE record, NVD detail page, and CISA KEV JSON feed. CISA's metadata lists Mitel MiCollab, dateAdded 2025-01-07, dueDate 2025-01-28, requiredAction guidance to apply mitigations per vendor instructions or discontinue use if mitigations are unavailable, and notes referencing the Mitel security advisory MISA-2024-0029 and the NVD entry. No CVSS score or version-specific impact details were provided in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-55550 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-55550

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-55550 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-55550

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.