Executive brief
The TP-240 (tp240dvr) component in Mitel MiCollab and MiVoice Business Express contains an access control vulnerability due to missing authentication. Remote attackers can exploit this to obtain sensitive information or trigger a denial of service via excessive outbound traffic, which has been used in 'TP240PhoneHome' reflection/amplification DDoS attacks.
Affected products
- Mitel MiCollab before 9.4 SP1 FP1
- Mitel MiVoice Business Express through 8.1
Timeline
- 2022-02: exploited: Exploitation first observed in the wild.
- 2022-03-08: disclosed: Public disclosure of the TP240PhoneHome DDoS attack vector.
- 2022-03-25: advisory: Mitel advisory and CISA KEV addition.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog.