CVE-2022-26143
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
A vulnerability in Mitel's TP-240 component allows attackers to access sensitive information and disrupt service by generating excessive traffic. This flaw was actively exploited in 2022 for large-scale DDoS attacks.
The TP-240 component in affected Mitel MiCollab and MiVoice Business Express versions lacks proper authentication controls (CWE-306), allowing unauthenticated remote attackers to trigger excessive outbound traffic and information disclosure. The vulnerability was weaponized for the TP240PhoneHome botnet DDoS campaign in early 2022.
The full analysis of this CVE is available in Portuguese →