CVE-2024-35286

Published Oct 21, 2024

Last updated 4 months ago

Overview

Description
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-89

Social media

Hype score
Not currently trending
  1. I've been analyzing newly disclosed vulnerabilities in popular systems, including Mitel MiCollab (CVE-2024-41713, CVE-2024-35286), Zyxel Firewalls (CVE-2024-11667), and Microsoft Windows (CVE-2024-35250, CVE-2024-49138). Ivanti is also affected (CVE-2025-0282, CVE-2025-0283).

    @agentwhitehat

    15 Jan 2025

    232 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Where There’s Smoke, There’s Fire 这篇报告深入剖析了 Mitel MiCollab 的 CVE-2024-35286、CVE-2024-41713 以及一个未公开的零日漏洞,揭示了该产品面临的严重安全风险。报告详细阐述了漏洞的成因、影响以及利用方式。 @watchtowrcyber Poc:https://t.co/mo7ePVwjgT https://t.co/Ew31fl5uKo

    @ZhupuW28641

    8 Jan 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 New @FortiGuardLabs Outbreak Alert: Security vulnerabilities in Mitel MiCollab have been uncovered, including CVE-2024-35286, CVE-2024-41713, and an arbitrary file read zero-day ⮕ https://t.co/ysYHPdG7Te https://t.co/UcndYU4blR

    @KazuMiyanishi

    18 Dec 2024

    28 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 New @FortiGuardLabs Outbreak Alert: Security vulnerabilities in Mitel MiCollab have been uncovered, including CVE-2024-35286, CVE-2024-41713, and an arbitrary file read zero-day ⮕ https://t.co/tVABv1FIH0 https://t.co/LbU5Vd1iX4

    @NaderAbdulrahma

    14 Dec 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 New @FortiGuardLabs Outbreak Alert: Security vulnerabilities in Mitel MiCollab have been uncovered, including CVE-2024-35286, CVE-2024-41713, and an arbitrary file read zero-day ⮕ https://t.co/kPZJMm4eIG https://t.co/oW3bbD8G5a

    @ujdmc

    13 Dec 2024

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 New #FortiGuardLabs Outbreak Alert: Security vulnerabilities in Mitel MiCollab have been uncovered, including CVE-2024-35286, CVE-2024-41713, and an arbitrary file read zero-day ⮕ https://t.co/KMeN9xWHti https://t.co/rcmldpKPmq

    @FortiGuardLabs

    13 Dec 2024

    5975 Impressions

    5 Retweets

    30 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Where There’s Smoke, There’s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day https://t.co/EESdexg8g6

    @akaclandestine

    8 Dec 2024

    554 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. #exploit 1. CVE-2024-46538: PfSense Stored XSS https://t.co/n9l7rTd3RF 2. CVE-2024-35286/41713: Mitel MiCollab SQLI / Path Traversal https://t.co/qtk8CPGTWx 3. CVE-2023-6200: Linux Kernel ICMPv6 Race Condtion https://t.co/gDhsyBkQLG

    @ksg93rd

    7 Dec 2024

    202 Impressions

    0 Retweets

    3 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  9. Top 5 Trending CVEs: 1 - CVE-2024-35286 2 - CVE-2024-3400 3 - CVE-2024-40834 4 - CVE-2024-43451 5 - CVE-2024-8636 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    7 Dec 2024

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. csirt_it: #Mitel: disponibili PoC per le CVE-2024-41713, CVE-2024-35286 e per una vulnerabilità zero-day relative al prodotto #MiCollab Rischio: 🔴 Tipologia: 🔸Arbitrary File Read 🔸Authentication Bypass 🔸Data Manipulation 🔗 https://t.co/s9aH02PmWP… https://t.co/ttMr0Y0ZqI

    @Vulcanux_

    6 Dec 2024

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2024-35286 & CVE-2024-41713:Critical Mitel MiCollab Flaw Exposes Systems to Unauthorized File and Admin Access thanks @watchtowrcyber for the POC... #bugbountytips #cve https://t.co/6L1j4mrP7T

    @AbdeladimeMk

    6 Dec 2024

    82 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨Alert🚨CVE-2024-35286 & CVE-2024-41713:Critical Mitel MiCollab Flaw Exposes Systems to Unauthorized File and Admin Access 🔥PoC: https://t.co/QZo7rhmCZN 🧐Deep Dive:https://t.co/3gIWyy7QfE 📊 14K+ Services are found on https://t.co/ysWb28BTvF yearly. 🔗Hunter Link:… https:/

    @HunterMapping

    6 Dec 2024

    2046 Impressions

    12 Retweets

    32 Likes

    12 Bookmarks

    1 Reply

    1 Quote

  13. Where There’s Smoke, There’s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day https://t.co/8Iqyd3smq8

    @tbbhunter

    5 Dec 2024

    704 Impressions

    4 Retweets

    11 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  14. Where There’s Smoke, There’s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day - watchTowr Labs https://t.co/6M2WpzsebG https://t.co/L43YZStK7e

    @secharvesterx

    5 Dec 2024

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 👀 we’ve watched APTs recently ravage lawful interception systems, and wanted our own capabilities… Join us on a journey today into Mitel’s MiCollab - that originally started to reproduce CVE-2024-35286, and quickly unravelled into more… https://t.co/KSiASEB4Cm

    @watchtowrcyber

    5 Dec 2024

    4919 Impressions

    34 Retweets

    91 Likes

    18 Bookmarks

    0 Replies

    2 Quotes

  16. CVE-2024-35286 A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient… https://t.co/hcukmyP5ZA

    @CVEnew

    23 Oct 2024

    314 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2024-35286 Unauthenticated SQL Injection Vulnerability in Mitel MiCollab NPM There is a SQL injection vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab up to version 9.8.0.33. This is because user in... https://t.co/ueQFMTYGPZ

    @VulmonFeeds

    22 Oct 2024

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes