Vendor
Mitel
As of , 7 Mitel vulnerabilities are on CISA's list of exploited vulnerabilities, 5 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2024-41713.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2024-41713Path Traversal | Mitel MiCollab | Patch this weekRansomware use; EPSS 0.98 | 0.98 | ||
| 2 | CVE-2022-29499Data Validation | Mitel MiVoice Connect | Patch this weekRansomware use; EPSS 0.55 | 0.55 | ||
| 3 | CVE-2022-26143Access Control | Mitel MiCollab, MiVoice Business Express | Patch this weekEPSS 0.87 | 0.87 | ||
| 4 | CVE-2024-55550Path Traversal | Mitel MiCollab | Patch this weekRansomware use | 0.38 | ||
| 5 | CVE-2022-40765Command Injection | Mitel MiVoice Connect | Patch this weekRansomware use | 0.11 | ||
| 6 | CVE-2022-41223Code Injection | Mitel MiVoice Connect | Patch this weekRansomware use | 0.11 | ||
| 7 | CVE-2024-41710Argument Injection | Mitel SIP Phones | Patch soon | 0.42 |
Products
- MiVoice Connect3 entries
- MiCollab2 entries
- MiCollab, MiVoice Business Express1 entry
- SIP Phones1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2022 | 2 |
| 2023 | 2 |
| 2024 | none |
| 2025 | 3 |
| 2026 | none |