Junglewise Threat Intelligence

CVE-2022-26143: MiCollab, MiVoice Business Express Access Control Vulnerability

CVE-2022-26143 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: Mitel MiCollab, Mitel MiVoice Business Express. Vendors: Mitel.

Executive brief

The TP-240 (tp240dvr) component in Mitel MiCollab and MiVoice Business Express contains an access control vulnerability due to missing authentication. Remote attackers can exploit this to obtain sensitive information or trigger a denial of service via excessive outbound traffic, which has been used in 'TP240PhoneHome' reflection/amplification DDoS attacks.

Affected products

  • Mitel MiCollab before 9.4 SP1 FP1
  • Mitel MiVoice Business Express through 8.1

Timeline

  • 2022-02: exploited: Exploitation first observed in the wild.
  • 2022-03-08: disclosed: Public disclosure of the TP240PhoneHome DDoS attack vector.
  • 2022-03-25: advisory: Mitel advisory and CISA KEV addition.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog.

Related threats