9.8
CVSSv3

CVE-2022-26143

Published: 10/03/2022 Updated: 08/08/2023
CVSS v2 Base Score: 9 | Impact Score: 8.5 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 802
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C

Vulnerability Summary

The TP-240 (aka tp240dvr) component in Mitel MiCollab prior to 9.4 SP1 FP1 and MiVoice Business Express up to and including 8.1 allows remote malicious users to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitel micollab 9.4

mitel mivoice business express

mitel micollab

Recent Articles

Mitel VoIP systems used in staggering DDoS attacks
The Register • Jeff Burt • 01 Jan 1970

Get our weekly newsletter One malicious network packet can theoretically spark billions more against a victim

Miscreants have launched massive, amplified distributed denial-of-service attacks by exploiting a vulnerability in Mitel collaboration systems. Their exploitation technique can, we're told, achieve an amplification factor of almost 4.3 billion to one, potentially, meaning a single malicious packet could bring down a stranger's network. An amplification attack typically involves sending a small amount of information to a vulnerable network service that causes it to reply with a much larger amount...