CVE-2022-26143criticalunder attackCWE-306

CVE-2022-26143

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 87%
from disclosure to weapon
Published on NVDMar 9
CISA KEV+16d
exploitation probability
87%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

A vulnerability in Mitel's TP-240 component allows attackers to access sensitive information and disrupt service by generating excessive traffic. This flaw was actively exploited in 2022 for large-scale DDoS attacks.

Technical detail

The TP-240 component in affected Mitel MiCollab and MiVoice Business Express versions lacks proper authentication controls (CWE-306), allowing unauthenticated remote attackers to trigger excessive outbound traffic and information disclosure. The vulnerability was weaponized for the TP240PhoneHome botnet DDoS campaign in early 2022.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a