VYPR
High severity8.8NVD Advisory· Published Oct 21, 2024· Updated Jun 17, 2026

CVE-2024-41714

CVE-2024-41714

Description

A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution Virtual Instance (MiVB SVI) through 1.0.0.27 could allow an authenticated attacker to conduct a command injection attack, due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands with elevated privileges within the context of the system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Mitel/Micollab3 versions
    cpe:2.3:a:mitel:micollab:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mitel:micollab:*:*:*:*:*:*:*:*range: <=9.8.1.5
    • (no CPE)
    • (no CPE)range: <=9.8 SP1 (9.8.1.5)
  • cpe:2.3:a:mitel:mivoice_business_solution_virtual_instance:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mitel:mivoice_business_solution_virtual_instance:*:*:*:*:*:*:*:*range: <=1.0.0.27
    • (no CPE)range: <=1.0.0.27

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.