• ABOUT
  • PRIVACY
  • CONTACT
  • ADVERTISE
No Result
View All Result
KeralaNews 24x7
Tuesday, July 1, 2025
  • HOME
  • NEWS
  • ENTERTAINMENT
  • CRYPTO
  • SPORTS
    • OLYMPIC
    • CRICKET
    • FOOTBALL
    • KABADDI
    • BASKETBALL
    • TENNIS
    • WWE
  • TECHNOLOGY
  • HEALTH
  • EVENTS
  • DEALS
    • SPECIAL DEALS
  • BLOG
    • BUSINESS
    • FINANCE
    • DIGITAL MARKETING
    • EDUCATION
    • LIFE STYLE
    • REAL ESTATE
    • ART
    • ADULT
    • CASINO
    • FASHION
    • GAMES
    • LAW AND ORDER
    • TRAVEL
  • HOME
  • NEWS
  • ENTERTAINMENT
  • CRYPTO
  • SPORTS
    • OLYMPIC
    • CRICKET
    • FOOTBALL
    • KABADDI
    • BASKETBALL
    • TENNIS
    • WWE
  • TECHNOLOGY
  • HEALTH
  • EVENTS
  • DEALS
    • SPECIAL DEALS
  • BLOG
    • BUSINESS
    • FINANCE
    • DIGITAL MARKETING
    • EDUCATION
    • LIFE STYLE
    • REAL ESTATE
    • ART
    • ADULT
    • CASINO
    • FASHION
    • GAMES
    • LAW AND ORDER
    • TRAVEL
No Result
View All Result
News 24x7
No Result
View All Result

CISA Flags Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server

Rahim Gupta by Rahim Gupta
6 months ago
Reading Time: 2 mins read
0
0
0
SHARES
0
VIEWS
FBXLinkedinWhatsAppTelegram

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three significant vulnerabilities impacting Mitel MiCollab and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog. These flaws, now under active exploitation, have raised alarms across the cybersecurity landscape due to their potential to enable unauthorized access and malicious activities.

The Vulnerabilities in Focus

Three vulnerabilities have been spotlighted for their criticality:

  • CVE-2024-41713 (CVSS score: 9.1): This path traversal flaw in Mitel MiCollab allows attackers to gain unauthorized and unauthenticated access to the system.
  • CVE-2024-55550 (CVSS score: 4.4): Another path traversal issue in Mitel MiCollab, enabling authenticated users with administrative privileges to read local files, owing to insufficient input sanitization.
  • CVE-2020-2883 (CVSS score: 9.8): A severe security vulnerability in Oracle WebLogic Server exploitable by unauthenticated attackers with network access via IIOP or T3.

The vulnerabilities carry differing levels of severity, but the potential to chain CVE-2024-41713 with CVE-2024-55550 has heightened concerns. This combination could enable remote, unauthenticated attackers to read arbitrary files, amplifying the risks associated with Mitel MiCollab systems.

Mitel MiCollab and Oracle WebLogic Server vulnerabilities

What Do We Know About Exploitation?

While technical details on real-world exploitation remain scarce, insights from WatchTowr Labs have shed some light on the vulnerabilities in Mitel MiCollab.

In their investigative efforts to replicate another critical flaw (CVE-2024-35286, CVSS score: 9.8) patched in May 2024, researchers identified the twin vulnerabilities. The findings suggest these flaws could be leveraged to compromise sensitive data and possibly disrupt communications infrastructure.

Oracle’s CVE-2020-2883, on the other hand, has a history of active exploitation attempts. Back in April 2020, Oracle warned that malicious actors had been targeting this vulnerability soon after its discovery, highlighting the urgency of patching.

Yet, the absence of information about specific targets or attack methods underscores the need for vigilance. Organizations relying on these platforms must prioritize mitigations to stay ahead of potential threats.

CISA’s Mandate and Timeline

In accordance with Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies have been instructed to apply necessary updates by January 28, 2025.

This directive aims to secure government networks and prevent attackers from exploiting known vulnerabilities. The urgency stems from the vulnerabilities’ high CVSS scores, reflecting their ease of exploitation and potential impact.

Key highlights of BOD 22-01:

  • Mandates timely remediation of vulnerabilities listed in the KEV catalog.
  • Focuses on improving cyber hygiene across federal networks.
  • Holds agencies accountable for adhering to patching deadlines.

The directive is a clear call to action, emphasizing proactive measures to strengthen security.

Broader Implications and Next Steps

These vulnerabilities serve as a reminder of the ongoing battle between attackers and defenders. As exploitation methods evolve, the responsibility to adapt lies not just with federal agencies but also with private organizations that depend on these systems.

For Mitel MiCollab users:

  • Ensure systems are updated to address CVE-2024-41713 and CVE-2024-55550.
  • Monitor for patches addressing related flaws, such as CVE-2024-35286.

For Oracle WebLogic users:

  • Validate that CVE-2020-2883 has been patched in your environment.
  • Regularly audit and test your security posture to identify any overlooked risks.

Ultimately, while CISA’s efforts provide essential guidance, the responsibility to act lies with organizations themselves. Ignoring these vulnerabilities could leave critical infrastructure exposed to potentially devastating consequences.

ShareTweetShareSendShare
Rahim Gupta

Rahim Gupta

Rahim Gupta, is a digital marketing maven known for his expertise in website optimization and SEO strategies. With an unwavering commitment to online success, he has guided countless businesses to new heights in the digital landscape. Rahim's concise, results-driven approach to SEO has made him a respected leader in the field.

Related Posts

Lhuan-dre Pretorius batting 2025 Zimbabwe Test

Teen Prodigies Shine Bright as Lhuan-dre Pretorius and Smriti Mandhana Etch Their Names in Cricket History

1 day ago
indian stock exchange trading floor

Nifty, Sensex Set for Subdued Start as Investors Await Global Cues

1 day ago
karlach baldur's gate 3 character close-up

Baldur’s Gate 3 Turns One—But Karlach’s Mind Flayer Ending Still Haunts Fans

3 days ago
Reeve Collins Chinh Chu SPAC crypto M-3 Brigade Acquisition Wikimedia

Crypto Financiers Aim for $1 Billion SPAC to Build Digital Asset Treasury

3 days ago
WhatsApp advertising interface updates tab screen

Meta has finally flipped the switch: WhatsApp is now officially an ad platform

7 days ago
google pixel 10 pro fold leak render

Google Pixel 10 Pro Fold Could Be the First Foldable Phone With Full IP68 Rating

7 days ago
tel aviv stock exchange building

Israeli Stocks Hit Record Highs After U.S. Strikes on Iran Nuclear Sites

1 week ago
diljit dosanjh sardaar ji 3 film trailer poster

Sardaar Ji 3 Stirs the Pot: Diljit Dosanjh Confirms Hania Amir Stays, Film Heads for Overseas-Only Release

1 week ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

ADVERTISEMENTS

(adsbygoogle = window.adsbygoogle || []).push({});

POPULAR ARTICLES

Mental Health

How Stress and Mental Health Affect Your Heart and Brain

2 years ago
monkey breeding

India’s need for monkey breeding and research facilities amid public health threats

2 years ago
eSports

Just How Big Will eSports Be?

8 years ago
Iontophoresis Device

Iontophoresis Device, the Best Treatment for Excessive Sweating

8 years ago
NOW Entertainment soon to Start Selling American Hustle82 Apparel

NOW Entertainment soon to Start Selling American Hustle82 Apparel

8 years ago
E-cigs Products in Classrooms

Is It Right to Ban the Juul and Other E-cigs Products in Classrooms?

8 years ago
Ryan Van Wagenen

Ryan Van Wagenen Expects Continued Growth for the Silicon Slopes

7 years ago
Working Remotely: Benefits for Employers and Employees

Working Remotely: Benefits for Employers and Employees

7 years ago
Benefits of installing Solar on your house

Benefits of installing Solar on your house

7 years ago
Casino Hacked using a Smart Thermometer

Casino Hacked using a Smart Thermometer

7 years ago
Facebook Twitter Youtube

ABOUT US

The KeralaNews 24×7 website is for desi entertainment lovers across India, USA and UK. We often cover breaking News & Trending topics in India and have been referenced by numerous media outlets. Follow us on our Social media profiles for the latest updates and news.

Contents produced in this website are subjected to DigitalCopyRight Law.

© 2023 KeralaNews 24×7 – Website Designed by VISION

WEBSITE STATS

  • Google News Approved
  • 1,00,000 Traffic/Month
  • Domain Authority – 25
  • 70% Traffic from Google

ADVERTISE WITH US

If you are looking to advertise your business or website, feel free to contact us at ceo.keralanews247@gmail.com

We accept following form of advertisements,

  • Banner Ads
  • Contextual Links
  • Guest Posts
  • Sponsored Posts

SEARCH

No Result
View All Result

MORE INFO

  • ABOUT
  • PRIVACY
  • CONTACT
  • ADVERTISE

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • NEWS
  • ENTERTAINMENT
  • CRYPTO
  • SPORTS
    • OLYMPIC
    • CRICKET
    • FOOTBALL
    • KABADDI
    • BASKETBALL
    • TENNIS
    • WWE
  • TECHNOLOGY
  • HEALTH
  • EVENTS
  • DEALS
    • SPECIAL DEALS
  • BLOG
    • BUSINESS
    • FINANCE
    • DIGITAL MARKETING
    • EDUCATION
    • LIFE STYLE
    • REAL ESTATE
    • ART
    • ADULT
    • CASINO
    • FASHION
    • GAMES
    • LAW AND ORDER
    • TRAVEL

© 2023 KeralaNews 24x7 - Website Designed by VISION

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.