ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hackers Abuse Mitel Devices to Amplify DDoS Attacks by 4 Billion Times

mediumVulnerabilityimportance 35CVE-2022-26143

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-26143
Unauthenticated access flaw in Mitel MiCollab and MiVoice Business Express (TP-240)

CVE-2022-26143 is a missing-authentication flaw (CWE-306) in the TP-240 (tp240dvr) component of Mitel MiCollab and MiVoice Business Express that allows any unauthenticated remote attacker to interact with the component over the network. By sending crafted requests, an attacker can obtain sensitive information and trigger performance degradation plus excessive outbound traffic from the appliance, with no privileges or user interaction required. The outbound-traffic behavior was abused in February and March 2022 in the TP240PhoneHome DDoS technique, in which vulnerable Mitel appliances were turned into powerful amplifiers, with public reporting describing amplification by a factor of roughly 4 billion. Organizations running MiCollab versions before 9.4 SP1 FP1 or MiVoice Business Express version 8.1 or earlier are affected, especially when the appliance is internet-reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-25 and carries an EPSS of 87.2% (100th percentile).

Do: Upgrade MiCollab to 9.4 SP1 FP1 (or later) and apply Mitel's current update for MiVoice Business Express 8.1, per vendor instructions as required by CISA's KEV catalog. Until patched, restrict internet exposure of the appliance and the TP-240/tp240dvr service via firewall rules or ACLs, and check logs for unexplained outbound traffic spikes or inbound probes to the component, which would indicate the system is being abused as a DDoS amplifier.

9.887% KEV PoC
  • Mitel MiCollab all versions before 9.4 SP1 FP1
  • Mitel MiVoice Business Express 8.1 and earlier (through 8.1)
largeon the order of 10,000+ internet-exposed Mitel appliances (public reporting of the 2022 abuse campaign indicated roughly 12,000 vulnerable devices were…
Full article484 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 09, 2022

Threat actors have been observed abusing a high-impact reflection/amplification method to stage sustained distributed denial-of-service (DDoS) attacks for up to 14 hours with a record-breaking amplification ratio of 4,294,967,296 to 1.

The attack vector – dubbed TP240PhoneHome (CVE-2022-26143) – has been weaponized to launch significant DDoS attacks targeting broadband access ISPs, financial institutions, logistics companies, gaming firms, and other organizations.

"Approximately 2,600 Mitel MiCollab and MiVoice Business Express collaboration systems acting as PBX-to-Internet gateways were incorrectly deployed with an abusable system test facility exposed to the public Internet," Akamai researcher Chad Seaman said in a joint advisory.

"Attackers were actively leveraging these systems to launch reflection/amplification DDoS attacks of more than 53 million packets per second (PPS)."

DDoS reflection attacks typically involve spoofing the IP address of a victim to redirect responses from a target such as DNS, NTP, or CLDAP server in such a manner that the replies sent to the spoofed sender are much bigger than the requests, leading to complete inaccessibility of the service.

First sign of the attacks is said to have been detected on February 18, 2022 using Mitel's MiCollab and MiVoice Business Express collaboration systems as DDoS reflectors, courtesy the inadvertent exposure of an unauthenticated test facility to the public internet.

"This particular attack vector differs from most UDP reflection/amplification attack methodologies in that the exposed system test facility can be abused to launch a sustained DDoS attack of up to 14 hours in duration by means of a single spoofed attack initiation packet, resulting in a record-setting packet amplification ratio of 4,294,967,296:1."

Specifically, the attacks weaponize a driver called tp240dvr ("TP-240 driver") that's designed to listen for commands on UDP port 10074 and "isn't meant to be exposed to the Internet," Akamai explained, adding "It's this exposure to the internet that ultimately allows it to be abused."

"Examination of the tp240dvr binary reveals that, due to its design, an attacker can theoretically cause the service to emit 2,147,483,647 responses to a single malicious command. Each response generates two packets on the wire, leading to approximately 4,294,967,294 amplified attack packets being directed toward the attack victim."

In response to the discovery, Mitel on Tuesday released software updates that disables public access to the test feature, while describing the issue as an access control vulnerability that could be exploited to obtain sensitive information.

"The collateral impact of TP-240 reflection/amplification attacks is potentially significant for organizations with internet-exposed Mitel MiCollab and MiVoice Business Express collaboration systems that are abused as DDoS reflectors/amplifiers," the company said.

"This may include partial or full interruption of voice communications through these systems, as well as additional service disruption due to transit capacity consumption, state-table exhaustion of network address translations, stateful firewalls, and so forth."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/03/hackers-abuse-mitel-devices-to-amplify.html