CVE-2022-26143
KEV PoC largeUnauthenticated access flaw in Mitel MiCollab and MiVoice Business Express (TP-240)
CISA: MiCollab, MiVoice Business Express Access Control Vulnerability
CVE-2022-26143 is a missing-authentication flaw (CWE-306) in the TP-240 (tp240dvr) component of Mitel MiCollab and MiVoice Business Express that allows any unauthenticated remote attacker to interact with the component over the network. By sending crafted requests, an attacker can obtain sensitive information and trigger performance degradation plus excessive outbound traffic from the appliance, with no privileges or user interaction required. The outbound-traffic behavior was abused in February and March 2022 in the TP240PhoneHome DDoS technique, in which vulnerable Mitel appliances were turned into powerful amplifiers, with public reporting describing amplification by a factor of roughly 4 billion. Organizations running MiCollab versions before 9.4 SP1 FP1 or MiVoice Business Express version 8.1 or earlier are affected, especially when the appliance is internet-reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-25 and carries an EPSS of 87.2% (100th percentile).
What to do: Upgrade MiCollab to 9.4 SP1 FP1 (or later) and apply Mitel's current update for MiVoice Business Express 8.1, per vendor instructions as required by CISA's KEV catalog. Until patched, restrict internet exposure of the appliance and the TP-240/tp240dvr service via firewall rules or ACLs, and check logs for unexplained outbound traffic spikes or inbound probes to the component, which would indicate the system is being abused as a DDoS amplifier.
| Mitel MiCollab | all versions before 9.4 SP1 FP1 |
| Mitel MiVoice Business Express | 8.1 and earlier (through 8.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
- Affected
- Mitel MiCollab, MiVoice Business Express
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mitel
- Products
- micollab, mivoice business express
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H