漏洞描述
The Mitel Collab Arbitrary File Read vulnerability allows an unauthenticated attacker to read arbitrary files from the underlying file system on a Mitel Collab server. Exploiting this flaw involves sending specially crafted requests to the server, bypassing access controls and allowing the attacker to retrieve sensitive files.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713↗labs.watchtowr.comhttps://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/↗www.mitel.comhttps://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029↗