{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2024-55550",
  "revision": 1,
  "title": "Mitel MiCollab — admin path traversal reads local files",
  "summary": "Mitel MiCollab through 9.8 does not sanitise input on one path, so an administrator can read files on the system. It is chained with an unauthenticated traversal in the same product.",
  "source_type": "cve",
  "severity": "medium",
  "cvss": {
    "score": 2.7,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
    "version": "3.1"
  },
  "epss": 0.37899,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2025-01-07",
    "prerequisites": "Administrative privileges on MiCollab — reachable through the companion flaw."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1083"
  ],
  "kill_chain": "collection",
  "recommended_action": "Apply the Mitel advisory fix now; it is chained with an unauthenticated traversal in the same product, so patch both or the chain still works.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-55550",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2024-55550",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2024-55550",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55550",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.mitel.com/support/security-advisories"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029"
    }
  ],
  "published_at": "2024-12-10T19:15:31.110Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "mitel",
    "micollab",
    "path-traversal",
    "ransomware",
    "kev"
  ]
}
