ZeroHour

CVE-2022-26143

KEV PoC large

Unauthenticated access flaw in Mitel MiCollab and MiVoice Business Express (TP-240)

CISA: MiCollab, MiVoice Business Express Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
87%p100
Published
()
KEV added
AI analysis

CVE-2022-26143 is a missing-authentication flaw (CWE-306) in the TP-240 (tp240dvr) component of Mitel MiCollab and MiVoice Business Express that allows any unauthenticated remote attacker to interact with the component over the network. By sending crafted requests, an attacker can obtain sensitive information and trigger performance degradation plus excessive outbound traffic from the appliance, with no privileges or user interaction required. The outbound-traffic behavior was abused in February and March 2022 in the TP240PhoneHome DDoS technique, in which vulnerable Mitel appliances were turned into powerful amplifiers, with public reporting describing amplification by a factor of roughly 4 billion. Organizations running MiCollab versions before 9.4 SP1 FP1 or MiVoice Business Express version 8.1 or earlier are affected, especially when the appliance is internet-reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-25 and carries an EPSS of 87.2% (100th percentile).

What to do: Upgrade MiCollab to 9.4 SP1 FP1 (or later) and apply Mitel's current update for MiVoice Business Express 8.1, per vendor instructions as required by CISA's KEV catalog. Until patched, restrict internet exposure of the appliance and the TP-240/tp240dvr service via firewall rules or ACLs, and check logs for unexplained outbound traffic spikes or inbound probes to the component, which would indicate the system is being abused as a DDoS amplifier.

Affected
Mitel MiCollaball versions before 9.4 SP1 FP1
Mitel MiVoice Business Express8.1 and earlier (through 8.1)
Estimated exposure
largeon the order of 10,000+ internet-exposed Mitel appliances (public reporting of the 2022 abuse campaign indicated roughly 12,000 vulnerable devices were… — These are enterprise on-prem unified communications appliances whose total installed base is larger but mostly internal; public scans and abuse observations around February-March 2022 showed thousands to tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CISA Known Exploited Vulnerability
Affected
Mitel MiCollab, MiVoice Business Express
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mitel
Products
micollab, mivoice business express
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news